ContraForce has many pages that are available depending on the deployed module. Below is an overview of what each icon represents, and associated page's functionality.
Name | Icon | Functionality | XDR | XDR + SIEM |
Command |
|
Main page to manage incidents for workspaces connected to ContraForce. | X | X |
Gamebooks |
|
All ContraForce gamebook activity for connected workspaces. | X | X |
Data Connectors |
|
Data connector overview for workspaces connected to ContraForce. | X | |
Endpoint |
|
Endpoint inventory for workspaces with Defender for Endpoint deployed. | X | X |
Workspaces |
|
List of all workspaces connected to the parent tenant. Workspaces can also be pre-onboarded and managed. | X | X |
SIEM Incidents |
|
Separate incidents page for SIEM module incidents. | X | |
Sentinel Advanced Threat Hunting |
|
Page dedicated to advanced threat hunting using KQL queries for Azure Sentinel. | X | |
XDR Incidents |
|
Separate incidents page for XDR module incidents. | X | X |
Defender XDR Advanced Threat Hunting |
|
Page dedicated to advanced threat hunting using KQL queries for Defender XDR. | X | X |
Settings |
|
Page to manage users. and notifications. | X | X |