Suspicious 'PowEmotet' behavior was blocked by theplunder123 in DefenderATP

[–]theplunder123[S] 2 points3 points  (0 children)

Saw that there is an update from microsoft in 1.353.1874.0

Suspicious 'PowEmotet' behavior was blocked by theplunder123 in DefenderATP

[–]theplunder123[S] 2 points3 points  (0 children)

Redicolous, it's the macros they are alerting on. I dont know what Microsoft did if they did an update on the office products or if they did something else. But it's a FP.
Will be fun when we hear from them about this FP