Home
%3CLINGO-SUB%20id%3D%22lingo-sub-1278807%22%20slang%3D%22en-US%22%3EWhat%E2%80%99s%20New%3A%20Improved%20Incident%20Closing%20Experience%20is%20now%20Available!%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1278807%22%20slang%3D%22en-US%22%3E%3CP%3E%3CEM%3EThis%20installment%20is%20part%20of%20a%20broader%20series%20to%20keep%20you%20up%20to%20date%20with%20the%20latest%20features%20in%20Azure%20Sentinel.%20The%20installments%20will%20be%20bite-sized%20to%20allow%20you%20to%20easily%20digest%20the%20new%20content.%3C%2FEM%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWhile%20the%20primary%20function%20of%20a%20SOC%20is%20providing%20situational%20awareness%20through%20the%20detection%2C%20containment%2C%20and%20management%20of%20security%20threats%3B%20this%20is%20coupled%20with%20the%20responsibility%20to%20track%20metrics%20to%20measure%20performance%20and%20to%20make%20changes%20to%20increase%20SOC%20efficiency.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EFrom%20our%20Microsoft%20CDOC%2C%20we%20have%20learned%20that%20the%20metrics%20you%20choose%20to%20measure%20has%20a%20significant%20effect%20on%20the%20behaviors%20and%20outcomes%20of%20security%20operations.%20Focusing%20on%20the%20right%20measurements%20will%20help%20drive%20continuous%20improvement%20in%20the%20right%20areas%20that%20meaningfully%20reduce%20risk.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EToday%2C%20we%20are%20happy%20to%20release%20%3CSTRONG%3Ethe%20improved%20incident%20closing%20experience!%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThis%20feature%20is%20meant%20to%20help%20customers%20track%20more%20detailed%20information%20on%20why%20incidents%20are%20closed.%20Being%20able%20to%20measure%20these%20metrics%20can%20allow%20you%20to%20enforce%20alert%20quality%20across%20your%20SOC%2C%20tune%20out%20false%20positives%2C%20and%20adjust%20processes%20to%20improve%20prioritization%20and%20focus.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EToday%2C%20incident%E2%80%99s%20status%20can%20be%20either%20New%2C%20In%20Progress%20or%20Close.%20When%20changing%20a%20status%20to%20'Close'%20you%20have%20an%20option%20of%20specifying%20whether%20the%20incident%20was%20a%20False%20Positive%20or%20a%20True%20Positive.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIn%20order%20to%20collect%20more%20information%20on%20the%20incident%20closing%2C%20we%20made%20this%20a%20mandatory%20field%20and%20provided%20a%20set%20of%20closing%20reasons%20that%20are%20based%20on%20researchers%20and%20customer%20references%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3ETrue%20Positive%2C%20suspicious%20activity%3C%2FLI%3E%0A%3CLI%3EBenign%20Positive%2C%20suspicious%20but%20expected%3C%2FLI%3E%0A%3CLI%3EFalse%20Positive%2C%20incorrect%20alert%20logic%3C%2FLI%3E%0A%3CLI%3EFalse%20Positive%2C%20inaccurate%20data%3C%2FLI%3E%0A%3CLI%3EUndetermined%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20image-alt%3D%22incidentclosing.gif%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F181967iF86935C429333110%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20title%3D%22incidentclosing.gif%22%20alt%3D%22incidentclosing.gif%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWe%20hope%20this%20feature%20will%20help%20customers%20better%20tune%20their%20rules%20and%20measure%20their%20SOC%E2%80%99s%20performance%20and%20will%20help%20us%20get%20more%20detailed%20information%20on%20our%20own%20detection's.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId-1758710297%22%20id%3D%22toc-hId--1381101398%22%20id%3D%22toc-hId--1381101398%22%20id%3D%22toc-hId--1381101398%22%20id%3D%22toc-hId--1381101398%22%20id%3D%22toc-hId--1381101398%22%20id%3D%22toc-hId--1381101398%22%3EGet%20started%20today!%3C%2FH2%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWe%20encourage%20you%20to%20use%20the%20improved%20incident%20closing%20experience%20in%20your%20environment.%3C%2FP%3E%0A%3CP%3ENote%20%E2%80%93%20The%20official%20documentation%20will%20be%20available%20in%201-2%20weeks.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ETry%20it%20out%2C%20and%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fbd-p%2FAzureSentinel%22%20target%3D%22_blank%22%20rel%3D%22noopener%22%20data-event%3D%22page-clicked-link%22%20data-bi-id%3D%22page-clicked-link%22%20data-bi-area%3D%22content%22%3E%26nbsp%3Blet%20us%20know%3C%2FA%3E%26nbsp%3Bwhat%20you%20think!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-1278807%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20are%20happy%20to%20release%20the%20improved%3CSTRONG%3E%20incident%3C%2FSTRONG%3E%20%3CSTRONG%3Eclosing%20experience.%3C%2FSTRONG%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThis%20feature%20is%20meant%20to%20help%20customers%20and%20us%20track%20more%20detailed%20information%20on%20why%20incidents%20are%20closed.%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1278807%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAnnouncements%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIncident%20Management%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1285389%22%20slang%3D%22en-US%22%3ERe%3A%20What%E2%80%99s%20New%3A%20Improved%20Incident%20Closing%20Experience%20is%20now%20Available!%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1285389%22%20slang%3D%22en-US%22%3E%3CP%3EPlease%20add%20a%20link%20on%20the%20Sentinel%20News%20%26amp%3B%20Guides%20blade%20to%20articles%20like%20this.%26nbsp%3B%20Also%2C%20the%20MCAS%20team%20has%20a%20very%20nice%20approach%20to%20tracking%20changes%2C%20see%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fcloud-app-security%2Frelease-notes%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fcloud-app-security%2Frelease-notes%3C%2FA%3E.%20It%20would%20be%20great%20if%20all%20of%20the%20security%20related%20teams%20used%20consistent%20methods%20of%20keeping%20us%20informed.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1296524%22%20slang%3D%22en-US%22%3ERe%3A%20What%E2%80%99s%20New%3A%20Improved%20Incident%20Closing%20Experience%20is%20now%20Available!%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1296524%22%20slang%3D%22en-US%22%3E%3CP%3EIs%20there%20any%20documentation%20explaining%20the%20difference%20between%20the%20below%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CUL%3E%3CLI%3EFalse%20Positive%2C%20incorrect%20alert%20logic%3C%2FLI%3E%3CLI%3EFalse%20Positive%2C%20inaccurate%20data%3C%2FLI%3E%3C%2FUL%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1333918%22%20slang%3D%22en-US%22%3ERe%3A%20What%E2%80%99s%20New%3A%20Improved%20Incident%20Closing%20Experience%20is%20now%20Available!%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1333918%22%20slang%3D%22en-US%22%3E%3CP%3E%22%3CSPAN%3Ea%20set%20of%20closing%20reasons%3C%2FSPAN%3E%22%3C%2FP%3E%3CP%3Ecould%20you%20give%20more%20explanation%20how%20each%20choice%20affects%20the%20Sentinel%20engine%20behavior%20or%20is%20it%20only%20a%20feedback%20about%20the%20incident%20rules%20quality%3F%3C%2FP%3E%3CP%3EWhich%20reason%20has%20the%20meaning%20%22that's%20totally%20OK%2C%20there's%20a%20support%20ticket%20for%20this%20action%22%3F%20I%20guess%20%22%3CSPAN%3Esuspicious%20but%20expected%22%20should%20be%20OK%2C%20but%20I%20would%20like%20to%20be%20sure%20%3B)%3C%2Fimg%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E

This installment is part of a broader series to keep you up to date with the latest features in Azure Sentinel. The installments will be bite-sized to allow you to easily digest the new content.

 

While the primary function of a SOC is providing situational awareness through the detection, containment, and management of security threats; this is coupled with the responsibility to track metrics to measure performance and to make changes to increase SOC efficiency.

 

From our Microsoft CDOC, we have learned that the metrics you choose to measure has a significant effect on the behaviors and outcomes of security operations. Focusing on the right measurements will help drive continuous improvement in the right areas that meaningfully reduce risk.

 

Today, we are happy to release the improved incident closing experience!

 

This feature is meant to help customers track more detailed information on why incidents are closed. Being able to measure these metrics can allow you to enforce alert quality across your SOC, tune out false positives, and adjust processes to improve prioritization and focus.

 

Today, incident’s status can be either New, In Progress or Close. When changing a status to 'Close' you have an option of specifying whether the incident was a False Positive or a True Positive.

 

In order to collect more information on the incident closing, we made this a mandatory field and provided a set of closing reasons that are based on researchers and customer references:

 

  • True Positive, suspicious activity
  • Benign Positive, suspicious but expected
  • False Positive, incorrect alert logic
  • False Positive, inaccurate data
  • Undetermined

 

incidentclosing.gif

 

We hope this feature will help customers better tune their rules and measure their SOC’s performance and will help us get more detailed information on our own detection's.

 

Get started today!

 

We encourage you to use the improved incident closing experience in your environment.

Note – The official documentation will be available in 1-2 weeks.

 

Try it out, and let us know what you think!

3 Comments
Respected Contributor

Please add a link on the Sentinel News & Guides blade to articles like this.  Also, the MCAS team has a very nice approach to tracking changes, see https://docs.microsoft.com/en-us/cloud-app-security/release-notes. It would be great if all of the security related teams used consistent methods of keeping us informed. 

Occasional Visitor

Is there any documentation explaining the difference between the below

 

 

  • False Positive, incorrect alert logic
  • False Positive, inaccurate data

 

Occasional Contributor

"a set of closing reasons"

could you give more explanation how each choice affects the Sentinel engine behavior or is it only a feedback about the incident rules quality?

Which reason has the meaning "that's totally OK, there's a support ticket for this action"? I guess "suspicious but expected" should be OK, but I would like to be sure ;)