Skip to content

Document AlertAndBlock action and clarify GenerateAlert mapping#504

Open
jongABCDsudo-rm-rf wants to merge 2 commits intoMicrosoftDocs:publicfrom
jongABCDsudo-rm-rf:docs-indicator-alertandblock
Open

Document AlertAndBlock action and clarify GenerateAlert mapping#504
jongABCDsudo-rm-rf wants to merge 2 commits intoMicrosoftDocs:publicfrom
jongABCDsudo-rm-rf:docs-indicator-alertandblock

Conversation

@jongABCDsudo-rm-rf
Copy link
Copy Markdown

Adds documentation for the AlertAndBlock action value supported by the Indicators API and clarifies its relationship to the existing BlockAndRemediate action and GenerateAlert parameter.

Indicators API accepts AlertAndBlock as a valid value for the action parameter, but it isn't listed in the supported parameters table on this page. Customers importing IoCs via CSV or calling the API directly currently have no documented reference for this value.

Functionally, AlertAndBlock on the API is equivalent to submitting action=BlockAndRemediate together with GenerateAlert=True. Seen in the Microsoft Defender portal, inputs render identically as Block and remediate with the Generate alert checkbox ticked.

@prmerger-automator
Copy link
Copy Markdown
Contributor

@jongABCDsudo-rm-rf : Thanks for your contribution! The author(s) and reviewer(s) have been notified to review your proposed change.

@learn-build-service-prod
Copy link
Copy Markdown
Contributor

Learn Build status updates of commit b8efdfd:

✅ Validation status: passed

File Status Preview URL Details
defender-endpoint/indicator-manage.md ✅Succeeded

For more details, please refer to the build report.

@learn-build-service-prod
Copy link
Copy Markdown
Contributor

Learn Build status updates of commit fc88a5f:

✅ Validation status: passed

File Status Preview URL Details
defender-endpoint/indicator-manage.md ✅Succeeded

For more details, please refer to the build report.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants