I would like an explanation on Sentinel's case closure.

Koonnamchok Klongkaew 160 Reputation points
2023-07-27T08:03:39.4266667+00:00

I would like an explanation on Sentinel's case closure.

Microsoft Security | Microsoft Sentinel
0 comments No comments
{count} votes

Answer accepted by question author
  1. Marilee Turscak-MSFT 37,371 Reputation points Microsoft Employee Moderator
    2023-07-27T22:45:30.4833333+00:00

    @Koonnamchok Klongkaew I understand that you are looking for explanations of the case closure reasons in Sentinel. I'm not sure if you are looking for criteria for choosing one of the categories or explanations of the category types, so I will try to provide both. Some of these descriptions are covered in the Sentinel documentation and the security alert documentation.

    True positive - suspicious activity - If you performed an investigation of a security issue and determined that the root cause was an actual threat, you can choose this category once you have remediated the issue.

    Benign positive - suspicious but expected - An action detected by Defender for Identity that is real, but not malicious, such as a penetration test or known activity generated by an approved application. A good example of this would be when someone elevates access to deploy a legitimate change. In most scenarios you would want to be notified about the elevated access, but in legitimate cases, this elevation would trigger a benign positive.

    False positive - incorrect alert logic - You can select this classification if you believe that the Analytics Rule logic that triggered the alert was configured incorrectly. This can be caused by your own misconfigured rules or by a misconfiguration in a template you were using.

    Undetermined - You should choose this category only if you are truly unable to determine what caused the incident, or if you think you might get a similar incident later but do not have enough info in the current one. This category should only be chosen in rare circumstances since ideally you should investigate the incidents and determine the root cause.

    Let me know if this helps and if you have futher questions.

    If the information helped you, please Accept the answer. This will help us as well as others in the community who may be researching similar questions.

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.