This post has been republished via RSS; it originally appeared at: New blog articles in Microsoft Community Hub.
Microsoft 365 Defender |
 |
Alert tuning is now generally available. Alert tuning lets you fine-tune alerts to reduce investigation time and focus on resolving high priority alerts. Alert tuning replaces the Alert suppression feature. We also published a blog on how to "Boost your detection and response workflows with alert tuning".
This animated GIF shows the new alert tuning
|
 |
(Preview) Custom functions: Custom functions are now available in advanced hunting. You can now create your own custom functions so you can reuse any query logic when you hunt in your environment.
|
 |
Ninja Show Season 4 is here! In this season we included a special mini-series on incident response, with lots of demos on how to investigate incidents following playbooks. Check out episode 1 "Investigation Capabilities in Microsoft 365 Defender". Add upcoming episodes to your calendar > https://aka.ms/ninjashow
Virtual Ninja Show Season 4 is here
|
 |
Implement Microsoft Sentinel and Microsoft 365 Defender for Zero Trust. This solution guide walks through the process of setting up Microsoft eXtended detection and response (XDR) tools together with Microsoft Sentinel to accelerate your organization’s ability to respond to and remediate cybersecurity attacks. |
 |
(GA) Automatic attack disruption is now generally available. This capability automatically disrupts human-operated ransomware (HumOR), business email compromise (BEC), and adversary-in-the-middle (AiTM) attacks.
Find more resources about Automatic attack disruption here.
Great blog post on how "how the built-in attack disruption capabilities in Microsoft 365 Defender help disrupt adversary-in-the-middle (AiTM)".
|
|
Microsoft Defender for Endpoint |
 |
Performance mode for Microsoft Defender Antivirus is now available for public preview. This new capability provides asynchronous scanning on a Dev Drive, and does not change the security posture of your system drive or other drives. For more information, see Protecting Dev Drive using performance mode.
|
|
Microsoft Defender for Cloud Apps |
 |
We are thrilled to introduce a new data type, called Behaviors in Microsoft 365 Defender, that will transform how you investigate alerts across all your workloads, starting with SaaS apps.
|

|
Behavior-generating policies no longer generate alerts (Preview). Starting May 28, 2023, policies that generate behaviors in Microsoft 365 Defender advanced hunting do not generate alerts. The policies will continue generating behaviors regardless of being enabled or disabled in the tenant's configuration. For more information, see Investigate behaviors with advanced hunting (Preview). |
 |
Non-blockable applications: To prevent users from accidentally causing downtime, Defender for Cloud Apps now prevents you from blocking business-critical Microsoft services. For more information, see Govern discovered apps.
|
|
Microsoft Defender for Identity |
|
Microsoft Defender for Office 365 |
|
Blogs on Microsoft Security |
|
|