A case that Microsoft Defender XDR or Microsoft Sentinel builds by correlating several alerts that look like parts of one attack. It lists the assets involved and the evidence, and analysts can assign it and update its status as they investigate.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Incident in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Defender XDR
Brings Defender products such as Cloud Apps, Identity, Office 365 and Endpoint together, joining their signals into incidents that span the time before and after a breach. Includes advanced hunting and automatic disruption of attacks.
- Microsoft Sentinel
Microsoft's cloud-native SIEM, with SOAR capabilities, which stores and queries its data in a Log Analytics workspace.
- LIKE
Compares strings with a pattern that can contain the % and _ wildcards. Because it only understands character patterns, searching big volumes of text this way is much slower than using full-text search.
- CRUD
Shorthand for create, read, update and delete, the four basic things you do with data. Data-plane roles in Azure Cosmos DB, for instance, authorise those operations on items.
Related terms
- Automatic attack disruption
A Microsoft Defender XDR feature that links signals into a high-confidence incident and, while ransomware, business email compromise or a similar attack is still in progress, contains the affected accounts and devices on its own. Security staff can reverse these actions.
- Automation rule
Microsoft Sentinel rule triggered when an incident or alert from any source is created or updated, used to centrally set status, assign owners, apply tags and launch playbooks.
- Bookmark
Lets a threat hunter keep a Microsoft Sentinel query result, along with notes, entity mappings and MITRE ATT&CK tags, then attach it to an existing incident or raise a fresh incident from it.
- Case management
Tracks SecOps work in the Defender portal as cases, either incident or generic, complete with SLA policies, attachments, comments, tasks and a history of changes. Sentinel in the Azure portal lacks it.
- Custom details
Lets Sentinel analytics rules and Defender custom detections pick fields from their query results and display them as key-value pairs on each alert and resulting incident.
- Defender Queue Assistant
A feature of the incident queue that rates every incident between 0 and 100 using machine learning and says what drove the score. Analysts can then tackle the most urgent incidents before the rest.
- Guided Network Troubleshooting
One-page investigation in VCF Operations for networks: pick a VM or application, and it maps dependencies, ties alerts and metrics together and highlights anomalies, logging the session as an incident.
- Guided responses
On an incident page in Defender, Security Copilot proposes next steps sorted under triage, containment, investigation and remediation, and points out anything automation has done already.