Utilizing threat investigation and response capabilities
Utilizing threat investigation and response capabilities in Microsoft Defender helps your organization quickly and effectively handle security threats. This recipe will walk you through the process of investigating and responding to threats using Microsoft Defender.
Getting ready
Ensure you have the Global Administrator or Security Administrator role to complete the steps in this recipe.
How to do it…
- Navigate to the Microsoft Defender portal at https://security.microsoft.com.
- Navigate to Incidents & alerts | Incidents to view the list of current security incidents. Figure 12.20 shows how you’re able to export, search, and filter results by date, status, severity, and more.
Figure 12.20 – Incidents screen of Microsoft Defender
- Select an incident to open the incident details pane. Then select Open incident page. Here, you can see the alerts that...