Manage Alerts and Incidents (part 2 of 3)
To read part 1 please click here To read part 3 please click here Manage Automatic Investigation Security Operations teams have always faced challenges in addressing the multitude of alerts that arise from the seemingly never-ending flow of threats, but the Microsoft Defender for Endpoint includes Automated Investigation and Remediation (AIR) capabilities that can help your security operations team address the threats more effectively and efficiently. AIR capabilities significantly reduce alert volume, allowing security operations to focus on more sophisticated threats and other high-value initiatives whereas the Action Center keeps track of all the investigations that were initiated automatically, along with details, such as the investigation status, detection source and any pending or completed actions. How the automated investigation starts? When an alert is triggered, a security playbook goes into effect and depending on the security playbook, an automated i...