Enriching machine timeline
You want more (data), we give it to you!
Machine timeline network events now includes:
- Port number
- The machine local DNS name (when relevant)
Network communications now includes port and local DNS values
Extending User Account support
Investigating a specific user account activities, on a given machine, in two clicks:
- Timeline filters now support filtering by specific account name - in the below example I filtered the timeline to show only activities conducted under 'tomerb' user account
- Keeping you in context! Want to know more information on this user without navigating elsewhere? Easy - you have the user side pane, to give you summarized information
User account focus views and toolset in the machine timeline
More summarized information everywhere
Following the positive feedback and popular demand, we have added the side pane with summarized information for machines and users to:
The alert queue, enabling quick review of the alerts and the details on the related machine / user |
|
The associated alerts pane section |
|
The organizational footprint section |
|
Updated Oct 19, 2017
Version 3.0Yarden Albeck
Microsoft
Joined July 23, 2017
Microsoft Defender for Endpoint Blog
When evaluating various solutions, your peers value hearing from people like you who’ve used the product. Review Defender for Endpoint by filling out a Gartner Peer Insights survey and receive a $25 USD gift card (for customers only). Microsoft Privacy Statement