Enriching machine timeline
You want more (data), we give it to you!
Machine timeline network events now includes:
- Port number
- The machine local DNS name (when relevant)
Network communications now includes port and local DNS values
Extending User Account support
Investigating a specific user account activities, on a given machine, in two clicks:
- Timeline filters now support filtering by specific account name - in the below example I filtered the timeline to show only activities conducted under 'tomerb' user account
- Keeping you in context! Want to know more information on this user without navigating elsewhere? Easy - you have the user side pane, to give you summarized information
User account focus views and toolset in the machine timeline
More summarized information everywhere
Following the positive feedback and popular demand, we have added the side pane with summarized information for machines and users to:
|
The alert queue, enabling quick review of the alerts and the details on the related machine / user |
|
|
The associated alerts pane section |
|
|
The organizational footprint section |
|
Microsoft Defender for Endpoint disrupts ransomware with industry-leading endpoint security, providing comprehensive protection across all platforms and devices.