1.7.575.57477 lots of "Reconnaissance using directory service enumeration"
Hi,
I am seeing a lot of "Suspicious Activity" in ATA relating to "Reconnaissance using directory services enumeration" from clients and servers.
I believe this was addressed in an earlier build of 1.7, am i safe to assume that these incidences are worthy of investigation?
Kind Regards
Pete Holland
Hi,
As you mentioned this is a known issue with ATA 1.7.
In some cases this suspicious activity can be caused by legitimate security solutions running on endpoints and servers. With ATA 1.7 Update 1 we've introduced the ability to disable this detection in order to stop generating these alerts. However it requires an additional manual step after deploying ATA 1.7 Update 1, which is decsribed at https://support.microsoft.com/en-us/help/3191777/description-of-update-1-for-microsoft-advanced-threat-analytics-v1.7We're further adding clustering and other elemets to the detection logic in the upcoming release of ATA to improve the detection itself and automatically address this scenario.
Hope this helps!
Michael.