Instiq
Chapter 4 · Responding to security incidents·v1.0.0·Updated 6/28/2026·~13 min

What's changed: Created SC-200 Chapter 4 (Domain 2: Defender XDR incident investigation/remediation (coverage of Defender for Office 365/Purview/Defender for Cloud workload protections/Defender for Cloud Apps/Entra ID ID Protection/Defender for Identity/Sentinel); complex attacks (multistage/multi-domain/lateral movement)/attack story (incident graph)/embedded Microsoft Security Copilot (agentic AI)/case management; Defender for Endpoint response (device timeline/live response/investigation package collection/evidence-entity investigation/automatic attack disruption); M365 investigation (Purview Audit/Purview eDiscovery Content search/Microsoft Graph activity logs)).

4.3Device response in Defender for Endpoint

Key points

Understand investigating device timelines, performing device actions (live response, collecting investigation packages), evidence/entity investigation, and responding to incidents identified by automatic attack disruption in Microsoft Defender for Endpoint.

On a suspected device, trace what happened chronologically and, if needed, operate remotely to contain it. Defender for Endpoint provides these as an EDR.

4.3.1Device timeline and evidence investigation

The device timeline shows events on a device (processes, files, network, registry) chronologically, reconstructing the attack. Investigate an incident’s evidence and entities (files/processes/IPs/users) to judge maliciousness. Analysts identify scope from the timeline and decide whether remediation is needed.

4.3.2Device actions and attack disruption

For remote response, use live response (shell into the device to fetch files, stop processes, run scripts), collect an investigation package (bulk forensic data), isolate the device, block files, etc. If automatic attack disruption (Chapter 1) has already isolated/contained the device, analysts confirm the result, investigate root cause, and release isolation after verifying safety.

Continue reading — free sign-up

You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.