Incident Run books


Viewing 1 post (of 1 total)
  • Author
  • Avatar


    I’m looking for run books that map to the alerts and Incident types created by Defender ATP

    The idea is to have the base run book and plan before the Incident rather than reacting afterwards

    I’m aware that one size does not fit all but im sure there are best practices

    Is there a way to get a list of all the Incident & Alert categories ?

    e.g. Inc:

    Horizontal port scan initiated
    Suspicious Powershell commandline
    Suspected credential theft activity

Viewing 1 post (of 1 total)

You must be logged in to reply to this topic.