Alerts and incidents
One of the areas where you will be spending time daily will be the Incidents & alerts node within the Microsoft Defender for Endpoint portal. Incidents & alerts is an area that will contain detailed information on all the alerts and incidents that are present in your environment. To fully understand the value of this node, we want to break down what each element brings to your security analysis.
First, let's cover alerts.
Alerts within Microsoft Defender for Endpoint are a critical item to bring to your attention. Alerts will be coming into Microsoft Defender for Endpoint for a multitude of reasons, with each alert having a trail for you to investigate and identify the root cause of each. This chapter will dive into both the alert portion as well as the incident investigation and evidence trail.
To begin, alerts will be visible through the Incidents & alerts node within Microsoft Defender for Endpoint. From there, you will be able to...