Forum Discussion

Kyrouz's avatar
Kyrouz
Copper Contributor
Oct 08, 2021

DeviceLogon events doesn't capture RDP connections (?!?!)

I create a custom detection that starts like this:   DeviceLogonEvents | where ActionType == "LogonSuccess" | where DeviceName has_any (Array of the backup servers) | where not(AccountName has_a...
  • Jake_Mowrer's avatar
    Jake_Mowrer
    Oct 13, 2021
    I will take a guess here, but it seems like I saw once where a customer had their audit policy overriding the items that Defender turns on. Try running this from an elevated command prompt and ensure the logon successes and failures are enabled:
    auditpol /get /category:*

    If this looks OK, I recommend opening case with our support team.

    Jake

Resources