Investigating and responding to alerts

The features for investigating and responding to alerts are explained in this section.

The following articles are in this section:

EDR rule updates

Working with the Alerts page

Understanding the Alert Detail page

Navigating the Respond page

Responding to alerts

Suppressing alerts

Leveraging the File Detail page

Leveraging collection and response extensions

Deploying the delete_file extension

What is the "ScreenConnect Suspicious Domain" alert?

What are "dual-use tool" detection rules?