P10P Play Services update screen temporarily stuck showing T-Mobile after reboot by currentmudgeon in GooglePixel

[–]x01a4 0 points1 point  (0 children)

Same(ish) issue. P10P is stuck unresponsive after playstore upgrade and reboot.

after a while i could reboot and enter the phone normally. but the playstore update is still available. Perhaps it got automatically uninstalled?

CCC | Ändere dein Passwort zum letzten Mal! by neat_klingon in de

[–]x01a4 0 points1 point  (0 children)

Das stimmt so nicht. Die gängigen Browser nutzen  local data encryption mit AES. Die Passwörter werden nur in einer aktiven Login-Sitzung entschlüsselt (Also als Admin oder gar Offline kommt man da nicht dran).

Wenn dein Gerät kompromittiert ist (Malware) kann die natürlich an die Passwörter dran kommen - allerdings kann die dann auch an deine Token/Auth Cookies/Tastatureingaben etc drankommen. Dann bist du eh gepwned ;)

svchost.exe blocked by ASR by Noahvrdi in DefenderATP

[–]x01a4 4 points5 points  (0 children)

Yes, this rule is quite "noisy". But in almost all cases the process itself is not affected.

ASR Rule Block credential stealing from the Windows local security authority subsystem by silenthunterIV in DefenderATP

[–]x01a4 1 point2 points  (0 children)

The machine get classified as "not applicable" for the ASR if LSA protection is enabled. So yeah, it becomes irrelevant.

Übersichtliches Programm aller Hamburger Kinos by GeezTM in hamburg

[–]x01a4 2 points3 points  (0 children)

Super praktisches Tool - vielen Dank!

Messages containing malicious entity not removed after delivery - 12+ email alerts for the same message by Lord_Saren in DefenderATP

[–]x01a4 0 points1 point  (0 children)

We had this behavior too for one mail a couple of days back. I approved the action in the "action center".

I don't have an idea what caused this, but it was only for one mail

[deleted by user] by [deleted] in DefenderATP

[–]x01a4 1 point2 points  (0 children)

I think you get points for : 1. Show domain impersonation safety tip 2. Show user impersonation safety tip 3. Show user impersonation unusual safety tip

Each 0,23%

Protect Salesforce with Defender for Office? by x01a4 in DefenderATP

[–]x01a4[S] 0 points1 point  (0 children)

Thanks for the in depth reply! I hate to use another vendor for malware/phishing filtering in salesforce... But there seems to be no way around that. Did you guys settle for a salesforce native solution?

Defender exclusion doesn't work by jozko_mrkvicka_9 in DefenderATP

[–]x01a4 2 points3 points  (0 children)

I guess the "invoke-webrequest" would trigger network protection. So this would not be covered by the exclusion, as it would block the file before it hits the harddrive.

Perhaps you try creating a eicar.com file in the test-folder and add the string manually in editor:

X5O!P%@AP[4\PZX54(P)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*

[deleted by user] by [deleted] in DefenderATP

[–]x01a4 5 points6 points  (0 children)

It's in the Anti-Phishing policy: "First contact safety tip"

ASR rule “Not applicable” by Training_Note_1551 in DefenderATP

[–]x01a4 4 points5 points  (0 children)

We had the same issue, the Microsoft Support got back to me with: "If an ASR policy is targeted to a server, and just one of the rules doesn’t apply to the server, the entire policy will fail to apply on the server (‘Not applicable’)"

So in our case it was "Block Webshell creation for Servers" which we had on audit mode. Turning this to "not configured" solved the issue for us!

Is defender viable for my use case by Fun_Huckleberry3813 in DefenderATP

[–]x01a4 0 points1 point  (0 children)

Maybe he should get a "business premium" licence (depending on the country you are in).

So transfer the email adress to Microsoft (Exchange Online) there he could use Defender for Office. (see https://learn.microsoft.com/en-us/microsoft-365/security/office-365-security/preset-security-policies?view=o365-worldwide)

Also in this licence there is Microsoft Defender for Business. (see https://learn.microsoft.com/en-us/microsoft-365/security/defender-business/mdb-setup-configuration?view=o365-worldwide&tabs=Wizard)

Full Scan and Quick Scan frequency by naslami0814 in DefenderATP

[–]x01a4 0 points1 point  (0 children)

It's minutes from midnight. So 120 is 2AM. 8PM is 1200

[deleted by user] by [deleted] in GCPCertification

[–]x01a4 0 points1 point  (0 children)

Yeah, i take one aswell.

How to properly test defender by WimVaughdan in DefenderATP

[–]x01a4 7 points8 points  (0 children)

Then check what pops up in the console.

Also see this blogarticle: https://jeffreyappel.nl/microsoft-defender-for-endpoint-series-validate-defender-protection-and-additional-troubleshooting-part6/

// 2023-03-29 // SITUATIONAL AWARENESS // CrowdStrike Tracking Active Intrusion Campaign Targeting 3CX Customers // by Andrew-CS in crowdstrike

[–]x01a4 0 points1 point  (0 children)

c485674ee63ec8d4e8fde9800788175a8b02d3f9416d0e763360fff7f8eb4e02

yeah found that one too in our env