Investigating and responding to alerts

The features for investigating and responding to alerts are explained in this section.

The following articles are in this section:

EDR rule updates

Working with the Alerts page

Understanding the Alert Detail page

Navigating the Respond page

Responding to alerts

Suppressing alerts

Leveraging collection and response extensions

Deploying the delete_file extension

What is the "ScreenConnect Suspicious Domain" alert?

What are "dual-use tool" detection rules?