Perform an automatic observable enrichment in Microsoft Defender for Endpoint
Perform an automatic observable enrichment in Microsoft Defender for Endpoint to enrich observables with additional information from various sources.
Antes de Iniciar
Verify that you have enabled the Security Incident Response system property. This option triggers the observable enrichment capability in SIR, whenever an observable is associated to a Security Incident.
Role required: sn_si.admin, sn_si.analyst
Por Que e Quando Desempenhar Esta Tarefa
You can use this capability during incident response investigations to contain an identified threat. When new observables are associated with the security incident, you can enable the observable enrichment in Microsoft Defender for Endpoint capability to run automatically.