Forum Discussion
John Louden
Aug 07, 2018Copper Contributor
Generating alerts
Hi all, We've starting rolling out EMS5 to our users, and have deployed the ATP Sensor on our dc's. The daily reports are working as expected but we have yet to see an alert. I've tried the FAQ t...
Tali Ash
Feb 05, 2019Former Employee
Hi Mtee- ,
Suspicious modifications of sensitive groups requires learning period of 4 weeks per DC.
The detection relies on events audited on domain controllers. Make sure your domain controllers are auditing the events needed.
Do you see any data in the Modification to sensitive groups report?
Thanks,
Tali
Mtee-
Feb 05, 2019Copper Contributor
Hello.
Thank you for the reply. Apparently my issue is that 4 week learning period.
Created AATP instance a week ago so that is the reason.
Thank you for the reply. Apparently my issue is that 4 week learning period.
Created AATP instance a week ago so that is the reason.