Forum Discussion

Chuck99's avatar
Chuck99
Brass Contributor
Sep 11, 2019

DNS reconnnaissance tests cannot be seen during the 8-day Learning Period

Hello, We are implementing Azure ATP and we have deployed sensors on our DCs. We want to test that the solution work by doing some network-mapping DNS reconnaissance activity (with nslookup) described in the lab testing documentation available here: https://docs.microsoft.com/en-us/azure-advanced-threat-protection/atp-playbook-reconnaissance#network-mapping-reconnaissance-dns

 

Unfortunately, we cannot see these activities on the Timeline page during the 8-day learning period as explained in the documentation. However, from what I read in the same documentation, we should be able to see the activities in the "Logical Activities timeline". However, we are not getting this information. I did the same test in another tenant and the result is the same. I even looked in the local ATP sensor log files that is in the DC and there's no information about these events.

 

  1. Am I missing something or is there an issue with this?
  2. Also, is there a way to change the learning period for some of the alerts to possibly reduce the duration?

PS: we are getting some other activities in the Timeline page (activities that doesn't require a learning period)

 

Thanks

6 Replies

  • Tali Ash's avatar
    Tali Ash
    Former Employee

    Hi Chuck99 ,

     

    The DNS activities supposed to be displayed in the computer timeline, not in the general alert timeline. Are you looking at the source computer profile you originated the DNS activities from. and there are no such activities? You can use the filter to look only at DNS queries. If this is the case please contact me privately with your tenant details so we can look at it.

     

    The learning period are not configurable.

     

    Thanks,

    Tali

    • Chuck99's avatar
      Chuck99
      Brass Contributor

      Hi Tali Ash 

       

      That's exactly right. I don't see the DNS activity in the source computer timeline. When I search for the source computer from where I did the DNS reconnaissance tests (pointing nslookup to the DC on which the ATP sensor is installed), I see other activities like logins or even SMB activities but not the DNS activities. Same thing if I run other reconnaissance commands like "net user /domain" or "net group "domain admins" /domain".

       

      I'll send you a private message with our tenant info. Thank you very much for your help with this.

      • PJR_CDF's avatar
        PJR_CDF
        Iron Contributor

        Chuck99 Tali Ash 

         

        I am seeing the exact same behaviour in my lab setup.

         

        Did you get to the bottom of this issue?

Resources