{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-338-check-defender-incident-pdf-coverage-and-freshness-before-using-it-as-evidence/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-338-check-defender-incident-pdf-coverage-and-freshness-before-using-it-as-evidence/",
        "slug": "dse-20260909-338-check-defender-incident-pdf-coverage-and-freshness-before-using-it-as-evidence",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-338-check-defender-incident-pdf-coverage-and-freshness-before-using-it-as-evidence/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-338-check-defender-incident-pdf-coverage-and-freshness-before-using-it-as-evidence.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-338-check-defender-incident-pdf-coverage-and-freshness-before-using-it-as-evidence/"
        },
        "title": "Check Defender incident PDF coverage and freshness before using it as evidence",
        "summary": "Can an incident PDF omit assets or evidence items and still be an expected export?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "cyber-defense",
            "label": "Cyber defense",
            "alt": "Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:26:18+00:00",
        "modified_at": "2026-09-10T01:40:03+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 250,
        "potentially_affected": "Authorized Microsoft Defender incident reviewers exporting incident information to PDF.",
        "dse_recommendation": "Record the PDF's selected sections, coverage limits and generation time alongside the incident reference.",
        "primary_source": {
            "name": "Manage incidents in Microsoft Defender - Microsoft Defender XDR | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/defender-xdr/manage-incidents",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Defender&#8217;s incident PDF includes up to ten impacted assets of each asset type and up to one hundred evidence items. The export dialog lets the operator include or exclude incident information, with everything selected initially. A generated report is cached briefly, so exporting the same incident again soon can return the earlier PDF; Microsoft advises waiting a few minutes for a newer version. <a href=\"https://learn.microsoft.com/en-us/defender-xdr/manage-incidents\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Apply this review when a PDF is used for handoff, offline analysis or an investigation record. Distinguish the exported presentation from a claim that every asset and evidence item in the live incident is present.</p>\n<h2>DSE recommendation</h2>\n<p>Record the PDF&#8217;s selected sections, coverage limits and generation time alongside the incident reference. Ask the investigator to identify any material evidence outside the displayed limits and preserve an authorized reference to it separately. After significant incident updates, do not repeatedly download the file and assume each download represents newly generated content. Keep the original export when it forms part of the investigation history.</p>\n<h2>Verification</h2>\n<p>Compare the exported asset and evidence lists with the incident&#8217;s current scope, especially where a category exceeds the documented cap. Inspect the report after the cache interval when a refreshed version is required, and confirm that the intended recent change appears. Label differences as omitted coverage, operator-selected exclusions or an earlier snapshot rather than treating every mismatch as lost incident data. Retain the comparison with the handoff.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/defender-xdr/manage-incidents\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Managing incidents and exporting PDF data</a>. Source reviewed September 9, 2026.</p>",
        "content_text": "Source facts\nDefender’s incident PDF includes up to ten impacted assets of each asset type and up to one hundred evidence items. The export dialog lets the operator include or exclude incident information, with everything selected initially. A generated report is cached briefly, so exporting the same incident again soon can return the earlier PDF; Microsoft advises waiting a few minutes for a newer version. Microsoft Learn.\nApplicability\nApply this review when a PDF is used for handoff, offline analysis or an investigation record. Distinguish the exported presentation from a claim that every asset and evidence item in the live incident is present.\nDSE recommendation\nRecord the PDF’s selected sections, coverage limits and generation time alongside the incident reference. Ask the investigator to identify any material evidence outside the displayed limits and preserve an authorized reference to it separately. After significant incident updates, do not repeatedly download the file and assume each download represents newly generated content. Keep the original export when it forms part of the investigation history.\nVerification\nCompare the exported asset and evidence lists with the incident’s current scope, especially where a category exceeds the documented cap. Inspect the report after the cache interval when a refreshed version is required, and confirm that the intended recent change appears. Label differences as omitted coverage, operator-selected exclusions or an earlier snapshot rather than treating every mismatch as lost incident data. Retain the comparison with the handoff.\nOfficial references\nMicrosoft Learn: Managing incidents and exporting PDF data. Source reviewed September 9, 2026.",
        "content_markdown": "## Source facts\n\nDefender’s incident PDF includes up to ten impacted assets of each asset type and up to one hundred evidence items. The export dialog lets the operator include or exclude incident information, with everything selected initially. A generated report is cached briefly, so exporting the same incident again soon can return the earlier PDF; Microsoft advises waiting a few minutes for a newer version. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-xdr/manage-incidents).\n\n## Applicability\n\nApply this review when a PDF is used for handoff, offline analysis or an investigation record. Distinguish the exported presentation from a claim that every asset and evidence item in the live incident is present.\n\n## DSE recommendation\n\nRecord the PDF’s selected sections, coverage limits and generation time alongside the incident reference. Ask the investigator to identify any material evidence outside the displayed limits and preserve an authorized reference to it separately. After significant incident updates, do not repeatedly download the file and assume each download represents newly generated content. Keep the original export when it forms part of the investigation history.\n\n## Verification\n\nCompare the exported asset and evidence lists with the incident’s current scope, especially where a category exceeds the documented cap. Inspect the report after the cache interval when a refreshed version is required, and confirm that the intended recent change appears. Label differences as omitted coverage, operator-selected exclusions or an earlier snapshot rather than treating every mismatch as lost incident data. Retain the comparison with the handoff.\n\n## Official references\n\n[Microsoft Learn: Managing incidents and exporting PDF data](https://learn.microsoft.com/en-us/defender-xdr/manage-incidents). Source reviewed September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-338-check-defender-incident-pdf-coverage-and-freshness-before-using-it-as-evidence/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-338-check-defender-incident-pdf-coverage-and-freshness-before-using-it-as-evidence/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-338-check-defender-incident-pdf-coverage-and-freshness-before-using-it-as-evidence/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Check Defender incident PDF coverage and freshness before using it as evidence",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-338-check-defender-incident-pdf-coverage-and-freshness-before-using-it-as-evidence/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-338-check-defender-incident-pdf-coverage-and-freshness-before-using-it-as-evidence/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-338-check-defender-incident-pdf-coverage-and-freshness-before-using-it-as-evidence/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-338-check-defender-incident-pdf-coverage-and-freshness-before-using-it-as-evidence/",
                "headline": "Check Defender incident PDF coverage and freshness before using it as evidence",
                "description": "Can an incident PDF omit assets or evidence items and still be an expected export?",
                "abstract": "Can an incident PDF omit assets or evidence items and still be an expected export?",
                "articleBody": "Source facts\nDefender’s incident PDF includes up to ten impacted assets of each asset type and up to one hundred evidence items. The export dialog lets the operator include or exclude incident information, with everything selected initially. A generated report is cached briefly, so exporting the same incident again soon can return the earlier PDF; Microsoft advises waiting a few minutes for a newer version. Microsoft Learn.\nApplicability\nApply this review when a PDF is used for handoff, offline analysis or an investigation record. Distinguish the exported presentation from a claim that every asset and evidence item in the live incident is present.\nDSE recommendation\nRecord the PDF’s selected sections, coverage limits and generation time alongside the incident reference. Ask the investigator to identify any material evidence outside the displayed limits and preserve an authorized reference to it separately. After significant incident updates, do not repeatedly download the file and assume each download represents newly generated content. Keep the original export when it forms part of the investigation history.\nVerification\nCompare the exported asset and evidence lists with the incident’s current scope, especially where a category exceeds the documented cap. Inspect the report after the cache interval when a refreshed version is required, and confirm that the intended recent change appears. Label differences as omitted coverage, operator-selected exclusions or an earlier snapshot rather than treating every mismatch as lost incident data. Retain the comparison with the handoff.\nOfficial references\nMicrosoft Learn: Managing incidents and exporting PDF data. Source reviewed September 9, 2026.",
                "datePublished": "2026-09-10T00:26:18+00:00",
                "dateModified": "2026-09-10T01:40:03+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-338-check-defender-incident-pdf-coverage-and-freshness-before-using-it-as-evidence/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-338-check-defender-incident-pdf-coverage-and-freshness-before-using-it-as-evidence/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Check Defender incident PDF coverage and freshness before using it as evidence"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 250,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Manage incidents in Microsoft Defender - Microsoft Defender XDR | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/defender-xdr/manage-incidents"
                }
            }
        ]
    }
}