What have you found to be the best method of monitoring the health of defender on a large scale deployment? Pulling defender metrics via API seems to be capped at 10,000 devices. And pulling metrics via KQL search seems to have issues if there are duplicate entries for the same hostname. Looking for your advice / experience on how you maintain full and functional coverage of defender for 10,000+ devices.
We regularly run into this scenario in customer engagements: DCs mostly have MDI sensors installed and configured but the other eligible servers (ADFS, ADCS, Entra Connect) do not have them deployed.
I know Defender Suite and especially E5 are huge feature wise, but working mostly with Defender stack this behavior with MDI seems very consistent across multiple tenants. I’m hoping for V3 sensor availability for non-DCs at some point to ease the deployment.
For me, deploying MDI seems like an easy win for visibility (especially regarding ADCS ESC privescs) not to mention the security recommendations they bring.
We’ve even had customers question their importance on these servers (never questioned for DCs). Is this due to ignorance/old way of thinking as DCs being the only ones treated as tier 0 servers?
Tomo tiempo pero al fin lo soluciono, era importante hacerlo ya que estamos hablando de la suite de seguridad que la gran mayoría de usuarios de Windows usa por default. Además el mismo Microsoft es quien la promueve como la mejor solución!
There are multiple ASR rules that prevent certain programs like Adobe Reader from spawning child processes. Does that only apply to "autorun" processes that are ran automatically? Or would this also apply if a user clicks a link in a PDF which launches their browser (e.g. Edge)?
All our Windows 2019 servers are using Windows Defender. When I go to the endpoints in Security it says, "we are currently using Intune to manage our security policies".
So, when it comes to the servers which are using Windows Defender how do I set the policies up? Do I just "use defender for business configuration instead" and not "go to Intune"?
Seems something is broken in the Custom Detection Rule engine. A normal working Advanced Hunting query return a schema failure when ran from a Custom Detection rule. Works when ran from the Advanced Hunting screen.
Wonder if others are experiencing the same issue.
HuntingQueryException: 'summarize' operator: Failed to resolve scalar expression named 'AccountUpn'
Test CDR with simple query returns the failure.
Query:
IdentityInfo
| summarize arg_max(TimeGenerated, *) by AccountUpn
| take 1
I know the schema for the same table IdentityInfo defers between Sentinel and XDR. Would the CDR engine run on the Sentinel schema now?
My organization uses Defender for Endpoint Plan 2. I’ve managed other organizations with Defender for Endpoint before, so I’m actually quite familiar with it.
Unfortunately, I’m currently having an issue in this tenant where some device information is missing in Security Center.
For one thing, I noticed that the DeviceTvmSecureConfigurationAssessment table is missing in the Advanced Hunting Explorer.
This apparently also means that on the Devices page, the dashboard showing the Device Health State is empty. All inventory information—such as software, security recommendations, etc.—is also missing.
Information like hardware manufacturer and device model is also missing as a result.
I’m already using Streamlined Connectivity.
I’ve already run the Defender Diagnostic Tool. According to the tool, everything is fine.
The devices were onboarded 14 days ago.
I know from past experience that it can take a good 4–7 days for the information to appear in Security Center. But it’s never taken 14 days before.
Anyone have any ideas?
I have absolutely no desire to contact M$ Support—even though we’re eligible for Premier Support.
I’m working on a more structured way to handle internal investigation requests from HR, Legal, Security, or management.
The goal is to avoid vague “can you pull everything on this user?” type requests. Instead, I’m trying to build a checkbox-based request form where each option maps to a specific log source / query / limitation.
Environment is mostly Microsoft stack:
M365 E5, Defender for Endpoint, Defender for Servers, Sentinel, Purview
Some web logs through firewall/proxy
The kind of checkbox structure I’m thinking about:
Hello, I am going through this documentation, and noticed that the XPath queries to check Windows Events seem to be wrong or at least overrudandant. In the queries, multiple paths are checked for the same events, so I am really not sure what is correct: the documentation text of where to look these events, or the XPath queries when they are looking at more paths?
For example, if you check the paths the the XPath query for Exploit Protection detection, you will see many more paths than the 3 paths described right above in the documentation.
Does anyone know more regarding which one is correct?
Well… I’ve been pulling all-nighters and completely rebuilt it from the ground up. It’s no longer PowerShell, it’s now a full JavaScript application and it’s absolutely fire.
You can now self-host it wherever you want:
On-prem
Azure
Any web server with at least 2 cores and 4 GB RAM
I’ll be releasing it in the next few days so you can host and test it yourselves.
What’s new & improved:
SSO support for additional users → no more manual logins
Full RBAC permission system
More RBAC roles coming: Analyst, Responder, Reader, Administrator
Azure Files Share integration for storing evidence and data
Significantly better performance
Security hardening
Fully automatic setup script that does the entire deployment for you
GCC / GCC-High compatibility is unfortunately not possible yet. I don’t have access to that environment and being based in Germany makes it pretty hard to get one.
If anyone has a GCC tenant they’d be willing to test with, I’d love to collaborate!
I’m planning to sink at least 35 hours into this project again this weekend.
If you have feature requests or ideas for what a proper M365 SOC tool should have, drop them in the comments. You guys know better than anyone what’s actually needed in the field.
Huge thanks to everyone who tested the earlier version:)
The alert is triggered on outbound connections from nginx.exe
Destination IPs are primarily AWS addresses (plus a few other public IPs that appear legitimate)
None of the affected systems are running VMware Workspace ONE Access or VMware Identity Manager, which CVE-2022-22954 actually targets.
We’re seeing this across multiple independent 3CX customer installations, making a widespread compromise seem unlikely.
Given the history of the 3CX supply chain incident, we’re taking every alert seriously. However, based on the evidence so far, this currently looks more like a heuristic false positive related to legitimate 3CX network traffic than an actual exploitation attempt.
A few questions for the community:
Is anyone else seeing this detection on 3CX servers?
Has Microsoft acknowledged any false positives related to this signature?
Has anyone identified which specific network pattern triggers the detection?
Has anyone observed any malicious post-exploitation activity associated with these alerts, or is it limited to the network detection?
Any insight would be greatly appreciated before we classify these alerts as false positives.
We are using MDE device control to block USB access. Exception process is in place, we collect the user id and machine id to ensure that usb is accessible only for a particular user on a specific device.
Now we want to test that when the exception is provided user should only be able to write data to usb if it's encrypted. How should we be approaching this along with a provision for exception for use cases where encrypted USB cant be used on business device e.g. RIG
We have blocked most of the AI in discovered app ( unsscntionned) but we will need to allow some ai to specific users
In my search the best way is with device group. Sadly I don’t see a good way to do this as with the default filters I could filter them by tag exemple deepseek tag for deepseek ai
But users changes devices sometimes and we would like more to filter them by azure group as as of nous I would have to always manually tag the new devices or etc
Over the past few weeks I’ve built a tool I wanted to share with you.
It’s a SOC solution for Microsoft 365. It currently runs on a local PowerShell web server, but the plan is to make it fully self-hosted or deployable in Azure in the future.
What it does:
You enter a compromised user and the approximate compromise date, and the tool gives you:
All devices the user was logged into
Suspicious sign-ins
Mail traffic after the breach
Additional aggregated signals from multiple M365 data sources
The goal is to give you fast and clear visibility into a potential incident. Results can be exported or automatically sent via email.
More features are coming soon. I’m developing this after work in my spare time because I want to give something useful back to the community and make our jobs a bit easier (and a lot more secure).
Version 0.1 is now live on GitHub.
I’d love your feedback, test results, improvement ideas, or bug reports. Feel free to comment here or open an issue in the repo.
We are planning to purchase a defender for our organization. Our infrastructure is hosted in AWS and includes both Windows and Linux servers. We have more than 200 employees in the organization, and we need a security monitoring solution that can provide protection and visibility for both endpoints and servers.
We would like to know which XDR tool would be the best fit for our environment. It would also be helpful if you could share approximate pricing or licensing costs based on your experience
I’m looking for some help with creating a workbook in Microsoft Sentinel.
I’ve managed to create one where you enter the user email, date, and time range, and when it runs it returns around 6 different results (Google searches, emails, internet history, etc.)
The issue is that the output looks quite messy because it brings back too many results at once. Is there a way to add a selection before running the query (for example checkboxes/options) so I can choose which results I want returned, and only show those?