Forum Discussion
MDE Alerts tab and quarantine files location
- Jun 26, 2024
Hello drivesafely,
The Alerts page (https://security.microsoft.com/alerts) supports filtering by Product name, which can be helpful if you're looking for MDE alerts without specifying the exact source within MDE product. You can achieve that by clicking on the "Add filter" option and choose Product name.
If you're still looking for Detection Source filter, you can export the Alerts page and filter in Excel.
Or, to filter alerts by detection source, you can use the following Advanced Hunting query:
AlertInfo
| where DetectionSource == "Source"
| project AlertId, Timestamp, DetectionSource, Title, Severity, Category
| sort by Timestamp descThe quarantine location you mentioned for MDAV is correct. Noting that it is recommended to only interact with Quarantine folder through Microsoft Defender/Windows Security App.
Best regards,
Adel
Hello drivesafely,
The Alerts page (https://security.microsoft.com/alerts) supports filtering by Product name, which can be helpful if you're looking for MDE alerts without specifying the exact source within MDE product. You can achieve that by clicking on the "Add filter" option and choose Product name.
If you're still looking for Detection Source filter, you can export the Alerts page and filter in Excel.
Or, to filter alerts by detection source, you can use the following Advanced Hunting query:
AlertInfo
| where DetectionSource == "Source"
| project AlertId, Timestamp, DetectionSource, Title, Severity, Category
| sort by Timestamp desc
The quarantine location you mentioned for MDAV is correct. Noting that it is recommended to only interact with Quarantine folder through Microsoft Defender/Windows Security App.
Best regards,
Adel
Thanks for the response and guidance.
I would like to take this oppurtunity to ask a question related to Alerts notification via email. We have configured the same, and receive quite limited information in the email. Is there a way to natively configure MDE to send more details we want in the email itself when it sent for any alert?
Regards,