×
google news

Exploring Microsoft Defender’s Advanced Incident Investigation Tools

Dive into Microsoft Defender's advanced incident investigation features, including attack stories, blast radius analysis, and evidence gathering for comprehensive threat remediation

Exploring Microsoft Defender's Advanced Incident Investigation Tools

The Microsoft Defender portal revolutionizes incident investigation by correlating alerts, assets, investigations, and evidence into cohesive incidents. This approach provides security professionals with a comprehensive view of attacks, enabling effective remediation planning. The portal’s intuitive interface guides users through the investigation process, from initial alert analysis to evidence gathering and remediation.

Security teams can begin their investigation by selecting an incident row, which opens a summary pane with key information. This pane includes the incident’s priority assessment, influencing factors, details, recommended actions, and related threats. Users can navigate through incidents using the up and down arrows at the top of the pane.

The main incident page offers a detailed attack story and tabs for alerts, devices, users, investigations, and evidence.

The Power of Attack Stories

Attack stories are a cornerstone of Microsoft Defender’s incident investigation capabilities. These stories provide a chronological narrative of the attack, allowing security professionals to review entity details and take remediation actions without losing context.

The attack story includes the alert page and an incident graph that visualizes the attack’s scope, spread, and impact over time.

The alert page is divided into sections, including the alert story, which details what happened, actions taken, and related events. Alert properties such as state, details, and description are displayed in the right pane. The incident graph connects suspicious entities with related assets like users, devices, and mailboxes, providing a visual representation of the attack’s progression.

From the graph, users can play alerts and nodes chronologically, open entity panes for detailed reviews and remediation actions, and highlight alerts based on related entities. The Go Hunt action leverages advanced hunting features to find relevant information about specific entities, such as devices, files, IP addresses, URLs, users, emails, mailboxes, or cloud resources.

Blast Radius Analysis: Visualizing Attack Paths

Blast radius analysis is an advanced graph visualization tool integrated into the incident investigation experience. Built on Microsoft Sentinel’s data lake and graph infrastructure, it generates an interactive graph showing possible propagation paths from a selected node to critical targets. This feature provides a unified view of both prebreach and post-breach information, helping security teams understand the scope of security incidents and enhance defensive measures.

To use blast radius analysis, users must be onboarded to Microsoft Sentinel data lake and have exposure management (read) permission or higher. The blast radius graph helps security analysts, IT administrators, SOC engineers, incident response teams, and security leaders assess risks, prioritize vulnerabilities, and plan defensive strategies. Users can view blast radius graphs by selecting an incident from the list and choosing the View blast radius option.

The blast radius graph displays the top-rated attack paths and a full list of paths on the right side panel. Users can explore paths by selecting listed targets and view potential paths from the entry point to the target. The graph includes icons representing nodes and edges, with explanations available in the documentation. Users can hide the blast radius graph and return to the original incident graph by selecting the node and choosing Hide blast radius.

Incident Details and Evidence

The incident details pane provides a comprehensive overview of an incident, including assignment, ID, classification, categories, and activity dates. It also includes a description of the incident, impacted assets, active alerts, and related threats. The incident description offers a brief overview, which may be derived from the first alert in the incident. Microsoft Sentinel customers can view and overwrite the incident description in the Azure portal.

The Evidence and Response tab displays all supported events and suspicious entities in the alerts. Microsoft Defender XDR automatically investigates these entities, providing information about important emails, files, processes, services, IP addresses, and more. Each analyzed entity is marked with a verdict (Malicious, Suspicious, Clean) and a remediation status, helping users understand the incident’s remediation status and next steps.

For incidents with a remediation status of Pending approval, users can approve or reject remediation actions, open in Explorer, or use the Go Hunt feature from within the Evidence and Response tab. The Summary page provides a snapshot of the incident’s importance, including alerts and impacted entities. It displays the number of impacted devices, users, and mailboxes, lists entities by risk level, and shows the alerts involved in the incident.


Contacts:
Henry Anderson

Henry Anderson of Edinburgh, sharp-corporate in demeanour, famously argued to run a council budget deep-dive after a packed Holyrood briefing, choosing public-accountability over easy headlines. Prefers evidence-led interrogation of institutions and collects annotated maps of the Lothians as a private quirk.