Security
Security events from devices, Microsoft 365 and network devices, the detections they raise, device protection and Cyber Essentials readiness.
- 1 Security overview What the Security area covers, where its events come from, and how to read the security overview page.
- 2 Working detections Triage, take, investigate and close detections, mark false positives, and follow the alert and ticket each one raised.
- 3 Searching security events Search every security event across devices, Microsoft 365, network devices and integrations, with the search language, saved searches, live tail and export.
- 4 Detection rules and suppressions The built-in detection rules, tuning a rule for one customer, testing and writing your own rules, and suppressing hits you do not want.
- 5 Event sources and collection Check that every device, tenant and network device is sending security events, choose what agents collect, and add firewalls and gateways that send syslog.
- 6 Device protection See each device's antivirus, EDR, firewall, disk encryption and local administrators, the findings against your limits, and the alerts when protection is lost.
- 7 Integrations and alerting Connect Microsoft Defender, SentinelOne and Huntress so their alerts become detections, and choose which detections raise alerts and tickets.
- 8 Cyber Essentials readiness See how ready each customer is for Cyber Essentials, what to fix first, their certificates, and export a readiness report for the customer or an assessor.