Skip to content

Commit 01d3dac

Browse files
authored
Merge branch 'main' into patch-21
2 parents c8b6b73 + b0bbbea commit 01d3dac

4 files changed

Lines changed: 22 additions & 9 deletions

File tree

microsoft-365/security/defender-endpoint/investigate-incidents.md

Lines changed: 4 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,8 @@
11
---
22
title: Investigate incidents in Microsoft Defender for Endpoint
33
description: See associated alerts, manage the incident, and see alert metadata to help you investigate an incident
4-
keywords: investigate, incident, alerts, metadata, risk, detection source, affected devices, patterns, correlation
5-
search.product: eADQiWindows 10XVcnh
64
search.appverid: met150
75
ms.service: defender-endpoint
8-
ms.mktglfcycl: deploy
9-
ms.sitesec: library
10-
ms.pagetype: security
116
ms.author: macapara
127
author: mjcaparas
138
ms.localizationpriority: medium
@@ -19,7 +14,7 @@ ms.collection:
1914
- mde-edr
2015
ms.topic: conceptual
2116
ms.subservice: edr
22-
ms.date: 12/18/2020
17+
ms.date: 01/24/2024
2318
---
2419

2520
# Investigate incidents in Microsoft Defender for Endpoint
@@ -44,6 +39,9 @@ When you investigate an incident, you'll see:
4439
4540
## Analyze incident details
4641

42+
> [!TIP]
43+
> For a limited time during January 2024, when you visit the **Incidents** page, Defender Boxed appears. Defender Boxed highlights your organization's security successes, improvements, and response actions during 2023. To reopen Defender Boxed, in the Microsoft Defender portal, go to **Incidents**, and then select **Your Defender Boxed**.
44+
4745
Click an incident to see the **Incident pane**. Select **Open incident page** to see the incident details and related information (alerts, devices, investigations, evidence, graph).
4846

4947
:::image type="content" source="images/atp-incident-details.png" alt-text="The details of an incident" lightbox="images/atp-incident-details.png":::

microsoft-365/security/defender-endpoint/manage-incidents.md

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ ms.collection:
1919
- mde-edr
2020
ms.topic: conceptual
2121
ms.subservice: edr
22-
ms.date: 12/18/2020
22+
ms.date: 01/24/2024
2323
---
2424

2525
# Manage Microsoft Defender for Endpoint incidents
@@ -36,6 +36,8 @@ ms.date: 12/18/2020
3636
3737
Managing incidents is an important part of every cybersecurity operation. You can manage incidents by selecting an incident from the **Incidents queue** or the **Incidents management pane**.
3838

39+
> [!TIP]
40+
> For a limited time during January 2024, when you visit the **Incidents** page, Defender Boxed appears. Defender Boxed highlights your organization's security successes, improvements, and response actions during 2023. To reopen Defender Boxed, in the Microsoft Defender portal, go to **Incidents**, and then select **Your Defender Boxed**.
3941
4042
Selecting an incident from the **Incidents queue** brings up the **Incident management pane** where you can open the incident page for details.
4143

microsoft-365/security/defender-endpoint/view-incidents-queue.md

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ ms.collection:
1919
ms.topic: conceptual
2020
ms.subservice: edr
2121
search.appverid: met150
22-
ms.date: 12/18/2020
22+
ms.date: 01/24/2024
2323
---
2424

2525
# View and organize the Microsoft Defender for Endpoint Incidents queue
@@ -33,6 +33,10 @@ ms.date: 12/18/2020
3333

3434
> Want to experience Defender for Endpoint? [Sign up for a free trial.](https://signup.microsoft.com/create-account/signup?products=7f379fee-c4f9-4278-b0a1-e4c8c2fcdf7e&ru=https://aka.ms/MDEp2OpenTrial?ocid=docs-wdatp-pullalerts-abovefoldlink)
3535
36+
> [!TIP]
37+
> For a limited time during January 2024, when you visit the **Incidents** page, Defender Boxed appears. Defender Boxed highlights your organization's security successes, improvements, and response actions during 2023. To reopen Defender Boxed, in the Microsoft Defender portal, go to **Incidents**, and then select **Your Defender Boxed**.
38+
39+
3640
The **Incidents queue** shows a collection of incidents that were flagged from devices in your network. It helps you sort through incidents to prioritize and create an informed cybersecurity response decision.
3741

3842
By default, the queue displays incidents seen in the last 6 months, with the most recent incident showing at the top of the list, helping you see the most recent incidents first.

microsoft-365/security/defender-endpoint/whats-new-in-microsoft-defender-endpoint.md

Lines changed: 10 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ ms.service: defender-endpoint
77
ms.author: macapara
88
author: mjcaparas
99
ms.localizationpriority: medium
10-
ms.date: 01/22/2024
10+
ms.date: 01/24/2024
1111
manager: dansimp
1212
audience: ITPro
1313
ms.collection:
@@ -50,6 +50,15 @@ For more information on Microsoft Defender for Endpoint on specific operating sy
5050
- [What's new in Defender for Endpoint on Android](android-whatsnew.md)
5151
- [What's new in Defender for Endpoint on iOS](ios-whatsnew.md)
5252

53+
## January 2024
54+
55+
- **Defender Boxed is available for a limited period of time**. Defender Boxed highlights your organization's security successes, improvements, and response actions during 2023. Take a moment to celebrate your organization's improvements in security posture, overall response to detected threats (manual and automatic), blocked emails, and more.
56+
57+
- Defender Boxed opens automatically when you go to the **Incidents** page in the Microsoft Defender portal.
58+
- If you close Defender Boxed and you want to reopen it, in the Microsoft Defender portal, go to **Incidents**, and then select **Your Defender Boxed**.
59+
- Act quickly! Defender Boxed is available only for a short period of time.
60+
61+
5362
## November 2023
5463

5564
- [Microsoft Defender Core service](microsoft-defender-antivirus-windows.md#microsoft-defender-core-service) is now available for consumers and is planned to begin rolling out to enterprise customers in early 2024.

0 commit comments

Comments
 (0)