You have a Microsoft Sentinel workspace.
You investigate an incident that has the following entities:
• A user account named User1
• An IP address of 192.168.10.200
• An Azure virtual machine named VM1
• An on-premises server named Server1
You need to label an entity as an indicator of compromise (IoC) directly by using the incidents page.
Which entity can you label?
Ramye
Highly Voted 8 months, 1 week agoRamye
7 months, 4 weeks agoMurtuza
Most Recent 10 months, 2 weeks agochepeerick
1 year agochepeerick
1 year agoAnil0512
1 year, 1 month agojamclash
1 year, 1 month agomali1969
1 year, 1 month agoFez786
1 year, 1 month agoRamye
8 months, 1 week ago