Microsoft Defender for IoT
General

Investigate incidents and alerts

In brief

The page refreshes metadata and clarifies how to investigate Defender for IoT incidents, use the DeviceInfo Site property in advanced hunting, and interpret the San Francisco site query.

What Defender admins need to know

Review the revised guidance when investigating incidents; no administrator action is specified.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Investigate incidents and alerts

Learn more about alert investigation in Microsoft Defender XDR and incident investigation in Microsoft Defender XDR in the Defender portal.

The following sections explainThis section explains how to investigate a Microsoft Defender for IoT incident and its associated alerts, and how to remediate the security issues raised by those alerts.they raise.

Alerts in the Incidents page uniquely combine IT and OT environment signals to detect potential threats and data leaks. The Incidents page displays:

Use advanced hunting to investigate IoT alerts

Advanced hunting is a query-based investigation feature in the Defender portal that lets you explore security data across your environment. Use the Site property listed in the DeviceInfo table to write queries for advanced hunting. ThisUsing the Site property allows you to filter devices according to a specific site, for example, all devices that communicated with malicious devices at a specific site.

The following query listsfilters the DeviceInfo table to return all endpoint devices with thethat match a specific public IP address at the San Francisco site.

DeviceInfo