Skip to content

Commit daf711f

Browse files
committed
Update incident classification images and clarify redaction note
Replaced logic app incident classification and recommendation screenshots with updated versions. Clarified the note about redacted IP addresses in the incident classification section for improved accuracy.
1 parent fb77499 commit daf711f

3 files changed

Lines changed: 1 addition & 1 deletion

File tree

1.03 KB
Loading
990 Bytes
Loading

articles/sentinel/datalake/sentinel-mcp-logic-apps.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -51,7 +51,7 @@ To install a preexisting logic app template:
5151

5252
When you create and run a playbook, insights from the entity analyzer appear as comments within an incident's details:
5353

54-
- The following screenshot shows the analyzer's top-level classification that a user account is compromised along with its supporting evidence, starting with the series of alerts and their associated [MITRE ATT&CK techniques](https://attack.mitre.org/), a list of malicious IP addresses the user signed in from, and a few suspicious user agents the user's activity originated from. The IP addresses have been redacted in this screenshot.
54+
- The following screenshot shows the analyzer's top-level classification that a user account is compromised along with its supporting evidence, starting with the series of alerts and their associated [MITRE ATT&CK techniques](https://attack.mitre.org/), a list of malicious IP addresses the user signed in from, and a few suspicious user agents the user's activity originated from. (The IP addresses have been redacted.)
5555

5656
:::image type="content" source="media/sentinel-mcp/logic-app-incident-classification.png" alt-text="Screenshot of the entity analyzer tool incident classification and evidence added to incident comments." lightbox="media/sentinel-mcp/logic-app-incident-classification.png":::
5757

0 commit comments

Comments
 (0)