Forum Discussion
edhealea
May 01, 2020Copper Contributor
Security principal reconnaissance (LDAP) (external ID 2038)
If downloading the details for this type of alert, shouldn't there be a list ofsuspected users attached within the download?
PeterRising
May 02, 2020MVP
How long have you had Azure ATP in place? Are you already getting these type of alerts, or is it still in its learning period as per - https://docs.microsoft.com/en-us/azure-advanced-threat-protection/atp-reconnaissance-alerts#security-principal-reconnaissance-ldap-external-id-2038
- edhealeaMay 04, 2020Copper Contributor
It has been install for over 6 months. We have had one of these alerts in the past week which prompted the question from by CSOC team. They were expecting to see users in the alert. PeterRising
- PeterRisingMay 04, 2020MVP
- edhealeaMay 05, 2020Copper ContributorWhich part of the alert do you want? The download details or actual alert in the console?