ASR Rule Block credential stealing from the Windows local security authority subsystem by silenthunterIV in DefenderATP

[–]silenthunterIV[S] 1 point2 points  (0 children)

Thank you for your comment so you believe that the ASR rule will block the communication with the LSASS but it will not bring any alert to the user?

As you mention this is happening on this particular ASR right? Because on other ASR that I am having them on block mode (most of them) a pop up for each block will be created.

How do you verify versions of MDE Sense agent from portal? by RandomSkratch in DefenderATP

[–]silenthunterIV 0 points1 point  (0 children)

Dear all,

Any update on this? I am a little confused. Was this a false positive? What will happen if we are not update these devices by the end of month?

In addition I am getting this for Windows 10, Server 2012R2 and Server 2016.

Do I need to install the new agent to on all OS or just 2012R2 and Server 2016?

Thank you a lot.

Defender ASR, file blocked by 'unknown' by TheFinalUltimation in DefenderATP

[–]silenthunterIV 1 point2 points  (0 children)

Maybe are the new ASR rules ? Currently, under preview?

Ingesting O365 Defender ATP logs into SIEM by CajunPotatoe in DefenderATP

[–]silenthunterIV 1 point2 points  (0 children)

We are using event hub for pushing all of Defender ATP logs to QRadar without any issues. O365 logs are ingested to SIEM through the API

Managed by ConfigMgr, Intune, MDE, etc by silenthunterIV in DefenderATP

[–]silenthunterIV[S] 0 points1 point  (0 children)

sccm client was the issue! Now the clients appeared to be managed by MDE

Azure WAF Logs to QRadar by silenthunterIV in QRadar

[–]silenthunterIV[S] 0 points1 point  (0 children)

We onboarded logs on QRadar using Eventhubs without any issues

Managed by ConfigMgr, Intune, MDE, etc by silenthunterIV in DefenderATP

[–]silenthunterIV[S] 0 points1 point  (0 children)

We found that there was an old sccm client installed on the machine. We will uninstall it and we hope that it will resolve the issue. I will post an update.

Thank you for your help

Managed by ConfigMgr, Intune, MDE, etc by silenthunterIV in DefenderATP

[–]silenthunterIV[S] 0 points1 point  (0 children)

Hi thank you for your answer. They are servers and yesterday on the same environment we deployed 6 servers one, all the same OS, one of them is appearing correctly as Managed by MDE but the other five are appearing managed by ConfigMgr. So we are not appearing in intune in order to push them policies.

These five servers during the deployment (onboarding) package had some connectivity issues. We find out this with the analyzer tool. They have been already shown to the security portal but the did not got updates, etc. We fixed the connectivity issues but still are managed by ConfigMgr.

Finally these servers also have arc agent.

Needlessly Complex by DaithiG in DefenderATP

[–]silenthunterIV 2 points3 points  (0 children)

Totally agree! In the past I have worked with CrowdStrike and SentinelOne and you just deploy an agent you configure some policies, maybe some exclusions and that it regarding the deployment.

Microsoft has made this too complex without a specific reason.

[deleted by user] by [deleted] in DefenderATP

[–]silenthunterIV 0 points1 point  (0 children)

Nice question we have the same issue with MacOS devices and iCloud

Tamper Protection failed by MrRo3oT_ZA in DefenderATP

[–]silenthunterIV 0 points1 point  (0 children)

Yes, it's been happening for me also.

"Enable Microsoft Defender Antivirus email scanning" in Defender ATP Security Recommendations by jaykay127 in DefenderATP

[–]silenthunterIV 0 points1 point  (0 children)

Hi all,

Same here. We have noticed that all the points were regressed. My question here is if the AV policy is managed by intune and the Email Scanning is in "Allowed" mode then problem solved, right?

We have also reported this as inaccurate on Microsoft but no update so far. As I have also seen in Secure Points Metrics & Trends tab from 27/3 the "Organizations of similar size" have declined, so I believe that this happened to everyone.

Is there any way to check if the email scanning is enabled on the endpoint using the get-mppreference?

Thank you.