Mitigate threats using Microsoft 365 Defender Flashcards
is an integrated threat protection suite with solutions that detect malicious activity across email, endpoints, applications, and identity.
Microsoft 365 Defender
Extended Detection and Response (XDR) combines signals from:
endpoints
identity
email
applications
Near real-time resolution of known incident types with automation. These are well-defined attacks that the organization has seen many times.
Automation
–Triage analysts focus on rapid remediation of a high volume of well-known incident types that still require (quick) human judgment. These are often tasked with approving automated remediation workflows and identifying anything anomalous or interesting that warrant escalation or consultation with investigation (Tier 2) teams.
Triage (aka Tier 1)
We recommend setting a quality standard of 90% true positive for any alert feeds that will require an analyst to respond so analysts aren’t required to respond to a high volume of false alarms.
90% true positive