Home
%3CLINGO-SUB%20id%3D%22lingo-sub-117719%22%20slang%3D%22en-US%22%3EWhat%E2%80%99s%20new%20in%20the%20WDATP%20Portal%3F%20July%2024th%2C%202017%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-117719%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSTRONG%3EAlert%20%26amp%3B%20machine%20reporting%20-%20Power%20BI%20content%20pack%20%3C%2FSTRONG%3E%3CEM%3E%5BInternal%20Preview%5D%3C%2FEM%3E%3C%2FP%3E%0A%3CP%3EWDATP%20Alert%20%26amp%3B%20machine%20statistics%20data%20is%20now%20consumable%20via%20a%20Power%20BI%20content%20pack%20and%20displays%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CSTRONG%3E%22Data%20Dashboard%3C%2FSTRONG%3E%3CSTRONG%3E%22%3C%2FSTRONG%3E%20-%20Summary%20of%20the%20past%20month%2C%20showing%3A%3CUL%3E%0A%3CLI%3E%3CU%3EMachine%3C%2FU%3E%3CU%3E%20statistics%3C%2FU%3E%3A%20Breakdown%20by%20machine%20health%20status%2C%20and%20by%20OS%20platform%3C%2FLI%3E%0A%3CLI%3E%3CU%3EAlerts%3C%2FU%3E%3A%20Breakdown%20by%3A%20severity%2C%20status%2C%20detection%20source%3C%2FLI%3E%0A%3CLI%3E%3CU%3EResolved%20alerts%3C%2FU%3E%3A%20Breakdown%20by%20severity%2C%20by%20detection%20source%2C%20by%20precision%2C%20and%20trend%20of%20resolved%20alerts%20(by%20day)%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F22347i9E1BEC691AAD4330%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%2235.jpg%22%20title%3D%2235.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3EClicking%20on%20any%20of%20the%20tiles%20will%20take%20you%20to%20the%20respective%20tab%20that%20drills%20down%20further%20into%20the%20data%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CSTRONG%3E%22Machines%20tab%22%3C%2FSTRONG%3E%20-%20Summary%20of%20the%20past%20month%2C%20showing%3A%3CUL%3E%0A%3CLI%3E%3CU%3EMachine%3C%2FU%3E%3CU%3E%20statistics%3C%2FU%3E%3A%20Breakdown%20by%20machine%20health%20status%2C%20OS%20platform%2C%20and%20domain%3C%2FLI%3E%0A%3CLI%3E%3CU%3EAlert%20statistics%3C%2FU%3E%3A%20List%20of%20machines%2C%20ranked%20by%20%23%20of%20reported%20alerts%2C%20alert%20breakdown%20by%20severity%20and%20status%2C%20by%20category%2C%20and%20by%20threat%20family%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F22376i2BB6B4A5B3040C3E%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%2232.jpg%22%20title%3D%2232.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CSTRONG%3E%22Alerts%20tab%22%3C%2FSTRONG%3E%20-%20Summary%20of%20the%20past%20month%2C%20showing%3A%3CUL%3E%0A%3CLI%3E%3CU%3EAlert%20%3C%2FU%3E%3CU%3Estatistics%3C%2FU%3E%3A%20Breakdown%20by%20severity%2C%20status%2C%20detection%20source%2C%20(machine)%20domain%2C%20category%2C%20threat%20family%3C%2FLI%3E%0A%3CLI%3E%3CU%3EAlert%20lists%3C%2FU%3E%3A%20ranked%20list%20of%20alerts%2C%20total%20number%20of%20alerts%2C%20and%20total%20number%20of%20machines%20reporting%20that%20alert%2C%20and%20a%20list%20of%20the%20reported%20alerts%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F22379i729EA69544302C37%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%2233.jpg%22%20title%3D%2233.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CSTRONG%3E%22Investigation%20results%20tab%22%3C%2FSTRONG%3E%20-%20Summary%20of%20the%20past%20month%2C%20showing%3A%3CUL%3E%0A%3CLI%3E%3CU%3EResolved%20Alerts%3C%2FU%3E%3CU%3E%20statistics%3C%2FU%3E%3A%20Breakdown%20by%20severity%2C%20detection%20source%2C%20daily%20trend%20(%23%20of%20alerts%20resolved)%2C%20and%20category%3C%2FLI%3E%0A%3CLI%3E%3CU%3EClassification%20and%20resolution%3C%2FU%3E%3A%20Average%20time%20to%20resolve%2C%20alert%20precision%2C%20breakdown%20by%20classification%20%26amp%3B%20resolution%2C%20and%20%23%20resolutions%20per%20analyst%3C%2FLI%3E%0A%3CLI%3EList%20of%20alerts%20and%20details%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F22381iAB36B08C6332AD55%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%2234.jpg%22%20title%3D%2234.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CEM%3ENote%3A%20Access%20to%20this%20feature%20is%20currently%20limited%20within%20Internal%20Preview%20and%20not%20%5Byet%5D%20fully%20exposed%20via%20the%20WDATP%20portal%20to%20all%20approved%20users%20on%20the%20MSIT%20tenant%3C%2FEM%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3ETagging%20in%20portal%20%3C%2FSTRONG%3E%3CEM%3E%5BInternal%20Preview%5D%3C%2FEM%3E%3C%2FP%3E%0A%3CP%3EWe%20now%20support%20adding%20custom%20tags%20to%20machines%20(e.g.%20SAWs%2C%20etc.)%2C%20to%20support%20easier%20filtering%20and%20focusing%20on%20customer-defined%20grouping.%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EFilter%20the%20Machines%20list%20by%20custom%20tag%2Fs%20%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F22382i2CE6BFC61EF758A7%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%2239.jpg%22%20title%3D%2239.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EManaging%20and%20applying%20custom%20tags%20to%20machines%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F22383i3B701457B6412C60%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%2240.jpg%22%20title%3D%2240.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3ECustom%20tags%20appear%20on%20the%20Machine%20page%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F22385iF6AA8E9A44A7EE6F%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%2242.jpg%22%20title%3D%2242.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3E%22Restrict%20code%20execution%22%20response%20action%20%3C%2FSTRONG%3E%3CEM%3E%5BInternal%20Preview%5D%3C%2FEM%3E%3C%2FP%3E%0A%3CP%3EIn%20this%20update%2C%20we're%20further%20enhancing%20response%20capabilities%20and%20adding%20the%20ability%20to%20disrupt%20%26amp%3B%20contain%20attacker%20activity%20by%20applying%20a%20lock%20down%20policy%20on%20potentially%20compromised%20machines%20to%20prevent%20execution%20of%20unknown%2C%20malicious%20programs.%3C%2FP%3E%0A%3CP%3EThe%20new%20%22Restrict%20code%20execution%3A%22%20response%20action%20will%20be%20available%20in%20the%20portal%20for%20Windows%2010%20machines%20running%20the%20Creators%20Fall%20(RS3)%20update.%3C%2FP%3E%0A%3CP%3ETo%20use%20this%20new%20capability%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3COL%3E%0A%3CLI%3EOpen%20the%20action%20menu%20and%20select%20%3CSTRONG%3E%22%3C%2FSTRONG%3E%3CSTRONG%3ERestrict%20code%20execution%22%3C%2FSTRONG%3E%3CSTRONG%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F22388i9D2FC10B14962C5D%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%2244.jpg%22%20title%3D%2244.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FSTRONG%3E%3C%2FLI%3E%0A%3CLI%3EType%20a%20comment%20(optional)%20and%20select%20yes%20to%20take%20action%20on%20the%20machine%3C%2FLI%3E%0A%3CLI%3EThe%20action%20center%20shows%20the%20submission%20information%20similarly%20to%20other%20response%20action%3C%2FLI%3E%0A%3CLI%3EWhen%20execution%20restriction%20action%20is%20applied%20on%20the%20machine%2C%20a%20new%20event%20is%20reflected%20in%20the%20machine%20timeline%3C%2FLI%3E%0A%3C%2FOL%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F22387iF00CFBA1A17F5C2F%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%2245.png%22%20title%3D%2245.png%22%20%2F%3E%3C%2FSPAN%3E%3CBR%20%2F%3E%20Note%3A%20undoing%20execution%20restriction%20is%20also%20possible%20from%20the%20console%20by%20opening%20the%20action%20menu%20and%20selecting%20%22Undo%20restrict%20code%20execution%22%20on%20a%20machine%20the%20action%20was%20previously%20applied%20on.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWe'd%20love%20to%20hear%20your%20feedback%20on%20the%20new%20features%20-%20that's%20it%20for%20this%20time!%3C%2FP%3E%3C%2FLINGO-BODY%3E
Microsoft

Alert & machine reporting - Power BI content pack [Internal Preview]

WDATP Alert & machine statistics data is now consumable via a Power BI content pack and displays:

  • "Data Dashboard" - Summary of the past month, showing:
    • Machine statistics: Breakdown by machine health status, and by OS platform
    • Alerts: Breakdown by: severity, status, detection source
    • Resolved alerts: Breakdown by severity, by detection source, by precision, and trend of resolved alerts (by day)

 35.jpg

Clicking on any of the tiles will take you to the respective tab that drills down further into the data:

  • "Machines tab" - Summary of the past month, showing:
    • Machine statistics: Breakdown by machine health status, OS platform, and domain
    • Alert statistics: List of machines, ranked by # of reported alerts, alert breakdown by severity and status, by category, and by threat family

 32.jpg

  • "Alerts tab" - Summary of the past month, showing:
    • Alert statistics: Breakdown by severity, status, detection source, (machine) domain, category, threat family
    • Alert lists: ranked list of alerts, total number of alerts, and total number of machines reporting that alert, and a list of the reported alerts

 33.jpg

  • "Investigation results tab" - Summary of the past month, showing:
    • Resolved Alerts statistics: Breakdown by severity, detection source, daily trend (# of alerts resolved), and category
    • Classification and resolution: Average time to resolve, alert precision, breakdown by classification & resolution, and # resolutions per analyst
    • List of alerts and details

 34.jpg

Note: Access to this feature is currently limited within Internal Preview and not [yet] fully exposed via the WDATP portal to all approved users on the MSIT tenant

 

Tagging in portal [Internal Preview]

We now support adding custom tags to machines (e.g. SAWs, etc.), to support easier filtering and focusing on customer-defined grouping.

Filter the Machines list by custom tag/s

 39.jpg

Managing and applying custom tags to machines

 40.jpg

Custom tags appear on the Machine page

 42.jpg

"Restrict code execution" response action [Internal Preview]

In this update, we're further enhancing response capabilities and adding the ability to disrupt & contain attacker activity by applying a lock down policy on potentially compromised machines to prevent execution of unknown, malicious programs.

The new "Restrict code execution:" response action will be available in the portal for Windows 10 machines running the Creators Fall (RS3) update.

To use this new capability:

 

  1. Open the action menu and select "Restrict code execution"44.jpg
  2. Type a comment (optional) and select yes to take action on the machine
  3. The action center shows the submission information similarly to other response action
  4. When execution restriction action is applied on the machine, a new event is reflected in the machine timeline

45.png
Note: undoing execution restriction is also possible from the console by opening the action menu and selecting "Undo restrict code execution" on a machine the action was previously applied on.

 

We'd love to hear your feedback on the new features - that's it for this time!