Forum Discussion

Jeff Harlow's avatar
Jeff Harlow
Iron Contributor
Aug 21, 2019
Solved

"Unusual volume of file deletion" Policy and Thumbs.db

I enabled the "Unusual volume of file deletion" policy and been ok for several months. Yesterday I received over 2 dozens alerts when it deleted a user "deleting" a bunch of "Thumbs.db" files.  She a...
  • Jeff Harlow's avatar
    Jeff Harlow
    Aug 21, 2019

    VasilMichev .. Noticed the same issue when I created a condition to rule out a user "NT AUTHORITY\SYSTEM" when granting mailbox permissions. It too shows as an equal while I have "User is None of These". Weird.  

     

    Thanks for catching the syntax. I changed it to filename instead of extension. Will see if that works now. 

     

    Microsoft seems to have abandoned these rules. I reported over a year ago certain criteria should not get flagged. For example, the granting permissions. I do not know what exactly is setting off the alert, but every week, I get at least one that "NT AUTHORITY\SYSTEM" has added permissions to a mailbox. This has been going on since they enabled alerts and yet to this day, I still get the alert.  I am hoping that adding the none of these to the alert, it will stop. I still want to know when someone grants permissions as that can be a sign of a hacker.