Microsoft Defender for IoT
General

Create attack vector reports in Microsoft Defender for IoT

In brief

The page metadata was refreshed, wording was updated to refer to potential attack paths, and the “Next steps” section was renamed “Related content” while retaining the same links.

What Defender admins need to know

Administrators can use the updated guidance and navigation; no action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Attack vector reports show a chain of vulnerable devices in a specified attack path, for devices detected by a specific OT network sensor. Simulate an attack on a specific target in your network to discover vulnerable devices and analyze attack vectors in real time.

Attack vector reports can also help evaluate mitigation activities to ensure that you're taking all required steps to reduce the risk to your network. For example, use an attack vector report to understand whether a software update would disrupt the attacker'sa potential attack path, or if an alternate attack path still remains.

Prerequisites

Generate an attack vector simulation so that you can view the resulting report.

To generate an attack vector simulation:

  1. Sign into the sensor console and select Attack vector on the left.
  2. Select Add simulation and enter the following values:

For more information, see Investigate sensor detections in the Device map.

Next stepsRelated content