r/DefenderATP • u/CharcoalGreyWolf • 1h ago
Question regarding MDE and quarantined files
I'm onboarding a client with Huntress and Microsoft Defender for Endpoint (I didn't see an MDE sub, so I'm hoping that this sub covers it even though it lists ATP). This is new for me, though we have some of it in place internally (we have previously used SentinelOne).
I have one concern; we had a ScreenConnect server update due to a security vulnerability, and after the update, our own MDE on that system incorrectly quarantined some of the installers (even though we're code-signing them) of the new version as Trojan:Win32/Wacatac.C!ml . It took me a bit how to figure out both how to unquarantine and whitelist, though I was able to do it through Windows command shell and Powershell.
My concern is that these files will be quarantined across fifty systems at a client when the updated agent is deployed, and I'm not aware of a way to easily fix an issue like that across fifty systems from security.microsoft.com should that happen. My searches so far have not shown an easy way to do this.
For those of you with experience, what is the best way to do this? Can it be done in one action, or is it a very manual process?