Threat response status allows you to to update and track the response status for a given threat in your tenant.
The available threat statuses are
- New: A detection event that has occurred in the last 24 hours.
- Open: An event that has not yet been marked as closed.
- Closed: An event that has been manually marked as closed by a user.
- Archived: An event that has been closed for over 30 days.
You can manually update the response status for a threat to Open or Closed, the New and Archived statuses are managed automatically as a threat is discovered or closed.
The threats list will show new, open, and closed threats, archived threats are hidden by default. You can also filter your threats based on their response status.
Devices in the side panel can also be filtered based on whether they have open or closed threat response status.
This feature is available within the Threats section for customers who have Endpoint Detection and Response enabled.
For more information, see our support article.
- Previous
- Next