# Check Defender incident PDF coverage and freshness before using it as evidence

> Can an incident PDF omit assets or evidence items and still be an expected export?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-338-check-defender-incident-pdf-coverage-and-freshness-before-using-it-as-evidence/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:26:18+00:00
- Modified: 2026-09-10T01:40:03+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

Can an incident PDF omit assets or evidence items and still be an expected export?

## Potentially affected

Authorized Microsoft Defender incident reviewers exporting incident information to PDF.

## DSE recommendation

Record the PDF's selected sections, coverage limits and generation time alongside the incident reference.

## Article

## Source facts

Defender’s incident PDF includes up to ten impacted assets of each asset type and up to one hundred evidence items. The export dialog lets the operator include or exclude incident information, with everything selected initially. A generated report is cached briefly, so exporting the same incident again soon can return the earlier PDF; Microsoft advises waiting a few minutes for a newer version. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-xdr/manage-incidents).

## Applicability

Apply this review when a PDF is used for handoff, offline analysis or an investigation record. Distinguish the exported presentation from a claim that every asset and evidence item in the live incident is present.

## DSE recommendation

Record the PDF’s selected sections, coverage limits and generation time alongside the incident reference. Ask the investigator to identify any material evidence outside the displayed limits and preserve an authorized reference to it separately. After significant incident updates, do not repeatedly download the file and assume each download represents newly generated content. Keep the original export when it forms part of the investigation history.

## Verification

Compare the exported asset and evidence lists with the incident’s current scope, especially where a category exceeds the documented cap. Inspect the report after the cache interval when a refreshed version is required, and confirm that the intended recent change appears. Label differences as omitted coverage, operator-selected exclusions or an earlier snapshot rather than treating every mismatch as lost incident data. Retain the comparison with the handoff.

## Official references

[Microsoft Learn: Managing incidents and exporting PDF data](https://learn.microsoft.com/en-us/defender-xdr/manage-incidents). Source reviewed September 9, 2026.

## Primary reference

- Name: Manage incidents in Microsoft Defender - Microsoft Defender XDR | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/defender-xdr/manage-incidents
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Check Defender incident PDF coverage and freshness before using it as evidence,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-338-check-defender-incident-pdf-coverage-and-freshness-before-using-it-as-evidence/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
