%3CLINGO-SUB%20id%3D%22lingo-sub-1580569%22%20slang%3D%22en-US%22%3EIntroducing%20an%20improved%20timeline%20investigation%20with%20event%20flagging%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1580569%22%20slang%3D%22en-US%22%3E%3CP%3E%3CEM%3E%3CSTRONG%3E%3CSPAN%20class%3D%22TextRun%20SCXW122393950%20BCX0%22%20data-contrast%3D%22none%22%3E%3CSPAN%20class%3D%22NormalTextRun%20SCXW122393950%20BCX0%22%3EUpdate%3A%20this%20integration%20is%20now%20generally%20available%20as%20of%20September%202020.%26nbsp%3B%3C%2FSPAN%3E%3C%2FSPAN%3E%3C%2FSTRONG%3E%3C%2FEM%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EMicrosoft%20Defender%20ATP%20offers%20a%20variety%20of%20ways%20for%20security%20teams%20to%20investigate%20and%20assess%20threats%20and%20other%20critical%20information.%20The%26nbsp%3Bdevice%20timeline%26nbsp%3Btab%20in%20the%20Microsoft%20Defender%20Security%20Center%20provides%20a%20chronological%20view%20of%20events%20and%20associated%20alerts%20that%20have%20been%20observed%20on%20the%20device.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWhile%20navigating%20the%20device%20timeline%2C%20you%20can%20search%20and%20filter%20for%20specific%20events%20to%20narrow%20down%20the%20list%20and%20help%20you%20pinpoint%20key%20information%20in%20your%20analysis.%20We%E2%80%99re%20excited%20to%20share%20that%20now%20you%20can%20also%20flag%20events%2C%20giving%20you%20the%20ability%20to%20%3CSTRONG%3Ehighlight%20and%20then%20quickly%20identify%20events%3C%2FSTRONG%3E%20that%20are%20of%20importance%20to%20you%20and%20your%20team.%20The%20new%20event%20flagging%20capability%20will%20enables%20your%20security%20team%20to%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3EHighlight%20the%20most%20important%20events%3C%2FLI%3E%0A%3CLI%3EMark%20events%20that%20require%20a%20deep%20dive%3C%2FLI%3E%0A%3CLI%3EBuild%20a%20clean%20breach%20timeline%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3ELet%E2%80%99s%20take%20a%20look%20at%20how%20to%20use%20this%20new%20feature.%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20image-alt%3D%22Blog.jpg%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F211742i4206700255C63DBE%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20title%3D%22Blog.jpg%22%20alt%3D%22Blog.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3COL%3E%0A%3CLI%3EStart%20by%20flagging%20events%20that%20you%20want%20to%20focus%20on%3COL%20class%3D%22lia-list-style-type-lower-alpha%22%3E%0A%3CLI%3ELocate%20the%20flag%20column%20in%20the%20device%20timeline%3C%2FLI%3E%0A%3CLI%3EFlag%20events%20by%20hovering%20over%20the%20flag%20column%20next%20to%20events%20and%20clicking%20on%20the%20events%20you%20wish%20to%20flag%3C%2FLI%3E%0A%3C%2FOL%3E%0A%3C%2FLI%3E%0A%3CLI%3EView%20the%20flagged%20events%3COL%20class%3D%22lia-list-style-type-lower-alpha%22%3E%0A%3CLI%3EIn%20the%20timeline%20filters%20section%2C%20toggle%20on%20%E2%80%9CFlagged%20events%E2%80%9D%3C%2FLI%3E%0A%3CLI%3EApply%20the%20filter%3C%2FLI%3E%0A%3C%2FOL%3E%0A%3C%2FLI%3E%0A%3CLI%3EIdentify%20flagged%20events%20on%20the%20time%20bar%20to%20help%20you%20build%20a%20clean%20breach%20timeline%3COL%20class%3D%22lia-list-style-type-lower-alpha%22%3E%0A%3CLI%3EClicking%20the%20flag%20on%20the%20time%20bar%20will%20only%20show%20events%20prior%20to%20the%20flagged%20event%3C%2FLI%3E%0A%3C%2FOL%3E%0A%3C%2FLI%3E%0A%3C%2FOL%3E%0A%3CP%3E%26nbsp%3B%26nbsp%3B%3C%2FP%3E%0A%3CP%3EApplying%20the%20filter%20allows%20you%20to%20%3CSTRONG%3Esee%20only%20the%20eight%20flagged%20events%20over%20the%20month%3C%2FSTRONG%3E%20amongst%20thousands%20of%20events!%3C%2FP%3E%0A%3CP%20class%3D%22lia-align-center%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20image-alt%3D%22Blog2.JPG%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F211744i3F3B74BD80E48313%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20title%3D%22Blog2.JPG%22%20alt%3D%22Blog2.JPG%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%20class%3D%22lia-align-center%22%3E%3CEM%3EExample%20of%20a%20clean%20timeline%3C%2FEM%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ETo%20learn%20more%20about%20the%20Microsoft%20Defender%20ATP%20device%20timeline%2C%20please%20read%20our%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fsecurity%2Fthreat-protection%2Fmicrosoft-defender-atp%2Fdevice-timeline-event-flag%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3Edocumentation.%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIf%20you%E2%80%99re%20not%20yet%20taking%20advantage%20of%20Microsoft%E2%80%99s%20industry%20leading%20security%20optics%20and%20detection%20capabilities%20for%20endpoints%2C%20%3CA%20href%3D%22https%3A%2F%2Fwww.microsoft.com%2Fmicrosoft-365%2Fwindows%2Fmicrosoft-defender-atp%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3Esign%20up%20for%20a%20free%20trial%3C%2FA%3E%20of%20Microsoft%20Defender%20ATP%20today.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-1580569%22%20slang%3D%22en-US%22%3E%3CP%3EMicrosoft%20Defender%20ATP%20offers%20a%20variety%20of%20ways%20for%20security%20teams%20to%20investigate%20and%20assess%20threats%20and%20other%20critical%20information.%20The%26nbsp%3Bdevice%20timeline%26nbsp%3Btab%20in%20the%20Microsoft%20Defender%20Security%20Center%20provides%20a%20chronological%20view%20of%20events%20and%20associated%20alerts%20that%20have%20been%20observed%20on%20the%20device.%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1580569%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EDevice%20timeline%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EEvent%20flagging%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E

Update: this integration is now generally available as of September 2020. 

 

Microsoft Defender ATP offers a variety of ways for security teams to investigate and assess threats and other critical information. The device timeline tab in the Microsoft Defender Security Center provides a chronological view of events and associated alerts that have been observed on the device. 

 

While navigating the device timeline, you can search and filter for specific events to narrow down the list and help you pinpoint key information in your analysis. We’re excited to share that now you can also flag events, giving you the ability to highlight and then quickly identify events that are of importance to you and your team. The new event flagging capability will enables your security team to:

  • Highlight the most important events
  • Mark events that require a deep dive
  • Build a clean breach timeline

 

Let’s take a look at how to use this new feature.

Blog.jpg

 

  1. Start by flagging events that you want to focus on
    1. Locate the flag column in the device timeline
    2. Flag events by hovering over the flag column next to events and clicking on the events you wish to flag
  2. View the flagged events
    1. In the timeline filters section, toggle on “Flagged events”
    2. Apply the filter
  3. Identify flagged events on the time bar to help you build a clean breach timeline
    1. Clicking the flag on the time bar will only show events prior to the flagged event

  

Applying the filter allows you to see only the eight flagged events over the month amongst thousands of events!

Blog2.JPG

Example of a clean timeline

 

 

To learn more about the Microsoft Defender ATP device timeline, please read our documentation.

 

If you’re not yet taking advantage of Microsoft’s industry leading security optics and detection capabilities for endpoints, sign up for a free trial of Microsoft Defender ATP today.