Loading...

Investigate incidents more effectively with the new attack story view in Microsoft 365 Defender

Investigate incidents more effectively with the new attack story view in Microsoft 365 Defender

One of the biggest efficiency drains for security operations center teams (SOC) is the constant switching of context – between different security tools or even between the various views within one solution when they’re looking for different types of information. These disconnected solutions and views cause SOC teams to lose valuable time while trying to manually piece together related signals.

 

Microsoft 365 Defender on the other hand correlates billions of signals across endpoints, cloud and on-prem identities, email, documents, and cloud apps and groups them into incidents – giving security teams a more effective way to investigate and remediate threats in a unified experience.

 

Today we’re excited to announce that we made the investigation experience even better with the introduction of attack story view in Microsoft 365 Defender - to help analysts stop breaches faster. In the new incident investigation experience in Microsoft 365 Defender, analysts can now easily navigate between affected assets or drill deep into the details of individual alerts, while always retaining the full context of the incident.

 

When you select an incident from the incident queue in Microsoft 365 Defender, the new attack story view is now the centerpiece of the investigation experience. It is a visual and interactive view of all affected resources, and it enables security analysts to understand the incident context at any point during their investigation. In addition, analysts can interact with the attack story view to determine next steps or take action from a dropdown with options.

 

Image 1 shows the new attack story view – it allows you to easily identify that in this case several users, files, an endpoint, an email account, as well as external domains are affected.  

 

Image 1 – New attack story view in Microsoft 365 DefenderImage 1 – New attack story view in Microsoft 365 Defender

 

 

Image 2 shows you what interacting with the new incident page looks like and how the views dynamically adjust to your actions. On the left-hand side of image 2 you can see the list of alerts tied to this incident – as analysts select the different alerts, the attack story view automatically adjusts to zoom in on the relevant alert and the incident page adjusts to provide all relevant details tied to this alert.

 

 

Image-2 Interactive views on the new incident pageImage-2 Interactive views on the new incident page

 

 

Alternatively, analysts can also engage directly with the graph to review the entity details by clicking on the relevant asset (image 3) and even select the action they want to take to further investigate or start remediation as shown in image 4.

Image 3 – Interact with the attack story view to retrieve device informationImage 3 – Interact with the attack story view to retrieve device information

 

 

 

 

Image 4: Select any of the available actions for further investigation or to start remediationImage 4: Select any of the available actions for further investigation or to start remediation

 

 

The new attack story view changes the game for SOC teams – gone are the days of never-ending context switching and trying not to lose sight of the overall incident and affected assets. The interactive view will make the investigation and response more intuitive and most importantly - help respond to threats faster and limit the impact of an attack.

 

 

For more information, check out these resources:

 

 

 

 

Published on:

Learn more
Microsoft 365 Defender Blog articles
Microsoft 365 Defender Blog articles

Microsoft 365 Defender Blog articles

Share post:

Related posts

Monthly news - November 2024

Microsoft Defender XDRMonthly newsNovember 2024 Edition This is our monthly "What's new" blog post, summarizing product updates and v...

1 year ago

Monthly news - August 2024

Microsoft Defender XDRMonthly newsAugust 2024 Edition This is our monthly "What's new" blog post, summarizing product updates and var...

1 year ago

Defender for Identity: the critical role of identities in automatic attack disruption

In today's digital landscape, cyber-threats are becoming increasingly sophisticated and frequent. Advanced attacks are often multi-workload an...

1 year ago

New Security Copilot skill: Identity Summary

“Can you summarize Defender insights about this user over the last two days?” Microsoft’s latest innovation for Copilot for Security, sim...

1 year ago

Demystify potential data leaks with Insider Risk Management insights in Defender XDR

In today's complex security landscape, understanding and mitigating data exfiltration risks is more critical than ever. Earlier this year, we ...

1 year ago

Monthly news - October 2024

Microsoft Defender XDRMonthly newsOctober 2024 Edition This is our monthly "What's new" blog post, summarizing product updates and va...

1 year ago

AI-Driven Guided Response for SOCs with Microsoft Copilot for Security

In today's evolving cybersecurity landscape, security operation centers (SOCs) are constantly bombarded with incidents ranging from minor aler...

1 year ago

Identity Summary: New Security Copilot skill within Defender XDR

“Can you summarize Defender insights about this user over the last two days?” Microsoft’s latest innovation for Copilot for Security, sim...

1 year ago

Detecting browser anomalies to disrupt attacks early

Detecting browser anomalies is crucial for early identification and prevention of cyber threats, preventing data breaches and attacks by monit...

1 year ago

Microsoft Defender for Identity: the critical role of identities in automatic attack disruption

In today's digital landscape, cyber-threats are becoming increasingly sophisticated and frequent. Advanced attacks are often multi-workload an...

1 year ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.