Microsoft Defender XDR
Incidents and response

Alert classification playbooks in Microsoft Defender XDR

In brief

The page title and headings now explicitly reference Microsoft Defender XDR. An Overview section and an anchor for the available playbooks section were added, and the publication date was updated.

What Defender admins need to know

No administrator action is required; the page now has clearer navigation and labeling.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Alert classification playbooks for Microsoft Defender XDR

[!INCLUDE Microsoft Defender XDR rebranding]

Overview

Alert classification playbooks allow you to methodically review and quickly classify the alerts for well-known attacks and take recommended actions to remediate the attack and protect your network. Alert classification will also help in properly classifying the overall incident.

As a security researcher or security operations center (SOC) analyst, you must have access to the Microsoft Defender portal so that you can:

  • FP for confirmed non-malicious activity.

Available alert classification playbooks

See these playbooks for steps to more quickly classify alerts for the following threats: