Detections View

When you receive a detection, it will appear in the Detections view of that particular tenant (organization).

Clicking on the Source will expand the event details view.

You can investigate the detection by viewing the event details, as well as relationships in the Timeline View.

You can also mark a detection as false positive if you don't want to receive any alerts for this particular D&R rule in the future. Clicking Mark False Positive from the detections view will open a FP rule editor and automatically populate the details of the event allowing you to edit & further customize the false positive rule.

Did this answer your question?