Respond to security incidents
Defender for Endpoint Investigation and Response
CoreReconstruct endpoint activity with timelines and entity pivots, collect the right evidence, and manage containment through verified recovery.
Aligned to SC-200 skills measured as of July 28, 2026; product behavior verified September 18, 2026.
Why this matters
Endpoint alerts summarize suspicious behavior, while the device timeline and evidence graph show delivery, execution, persistence, and network impact. Response choices should preserve artifacts and stop active access without confusing isolation with eradication.
Must Know
- Anchor timeline review on reported symptoms, alert time, process, hash, user, or IP, then expand to parent-child and network context.
- Live response provides an authorized interactive endpoint session; an investigation package collects a standard artifact bundle for offline review.
- File, certificate, IP, process, user, and device entities gain meaning from prevalence, observation, execution, and relationship context.
- Review automatic disruption actions and the correlated attack evidence. Remove persistence and verify related entities before reversing containment.
Compare and Distinguish
- The device timeline is chronological telemetry; the incident graph emphasizes entity relationships and attack progression.
- Live response provides a controlled remote shell; an investigation package gathers a defined artifact bundle for offline analysis.
- Device isolation is containment; file quarantine or removal is remediation; collecting evidence is investigation.
Scenario examples
- Scenario: Analysts need to know what ran immediately before an alert. Think: filter the device timeline around the event.
- Scenario: A responder must run a signed investigation script remotely. Think: use live response with the required permission.
- Scenario: Attack disruption isolated an account or device. Think: validate the incident evidence before completing or reversing remediation.
Exam traps
- An investigation package does not execute an interactive diagnostic script.
- A familiar filename, signed certificate, or sanctioned IP can still appear in malicious context.
- Closing an alert does not collect artifacts, stop a process, or release an isolated device.
- A password reset does not remove a scheduled task from an endpoint.
Key takeaways
- Use time and entity anchors to reduce timeline noise.
- Select live response for targeted interaction and an investigation package for broad collection.
- Release devices and accounts only after the attack path and persistence are cleared.
How it works
- The device timeline orders endpoint events and allows pivots into files, processes, users, IPs, and related alerts.
- Response actions change device or artifact state and remain visible in Action center for review or reversal.
Objects and administrative surfaces
- Device page timeline, alerts, logged-on users, software, vulnerabilities, and response actions.
- Live response session with audited commands and role requirements.
- Incident attack story and action center for automatic and manual actions.
When to use it
- Use entity pages to measure prevalence and observations across devices.
- Use automatic disruption evidence when deciding whether containment should remain during remediation.
Security and governance implications
- Restrict live-response permissions and signed-script use to authorized responders.
- Collect volatile evidence before reimaging and document every manual or automated endpoint action.
Troubleshooting signals
- If evidence collection fails, check device connectivity, action status, and permission before weakening protection.
- If a familiar artifact looks suspicious, compare hash, signer, path, parent process, time, and network behavior.
More detail
- Anchor timeline review on reported symptoms, alert time, process, hash, user, or IP, then expand to parent-child and network context.
- Live response provides an authorized interactive endpoint session; an investigation package collects a standard artifact bundle for offline review.
- File, certificate, IP, process, user, and device entities gain meaning from prevalence, observation, execution, and relationship context.
- Review automatic disruption actions and the correlated attack evidence. Remove persistence and verify related entities before reversing containment.
Ready for the quiz?
- Which action preserves standard forensic artifacts before reimaging?
- What extra context resolves an IP used by both a scanner and malware?
- What must be true before automatic containment is reversed?
Related objectives
- D2.2.S1 — Investigate device timelines
- D2.2.S2 — Perform actions on the device, including live response and collecting investigation packages
- D2.2.S3 — Perform evidence and entity investigation
- D2.2.S4 — Investigate and remediate incidents identified by automatic attack disruption