Forum Discussion
MDE repeatable false positive "Multi-stage incident involving Privilege escalation..." How to fix?
I know! The guids do vary, too, the one from a week ago (same incident comprised of exactly 57 alerts, mind you). Wonder if the indicators are poisoned somehow even though I'm not seeing after listing in the API.
- MaheshMarthiNov 15, 2023MCTmake sure you have access to existing TI projects. While creating a new one , it shows "accessible to Me" option.
- MaheshMarthiNov 15, 2023MCTThere is a section called Threat Intelligence. if you dont find it, try going to
https://ti.defender.microsoft.com/projects?tab=team - Nov 01, 2023do you any special agent on your devices that run every 7 days for example and send data somewhere other than MDE ?
- ActualCassandraNov 01, 2023Copper ContributorNo, that is what makes it so strange. I have even used the API to list indicators and there is nothing there to trigger something like the incident above.
- Oct 31, 2023
ActualCassandra you dont have any custom indicators in your MDE settings ?
- ActualCassandraOct 31, 2023Copper Contributor
OK, this happens every seven days at the exact same time, when Windows 10 is carrying out its behind the scenes operating system scheduled tasks. Example (similar to the original screenshot):
- ActualCassandraOct 24, 2023Copper Contributor
elieelkarkafiHi - yes, the latest are new machines from scratch. I even tried a VM in Azure this time around since the other ones were on-prem in VMware.
I just don't understand the 'Custom TI' detection source. We get other alerts which show this and you can tell that they are related to the the Endpoint settings under Rules, Indicators. The only section with any entries is URLs/Domains and any alert related to those settings is correctly named as a connection to a custom network indicator. However, these multi-stage attack incidents don't show as having any indicators, even when I call the MDE API and have it list indicators.
- Oct 24, 2023did you try to create a greenfield machine without installing any app on it and just onboarded to MDE and see if will automatically trigger the same false positive alerts ? what version of windows 10 \11 are you using ?
- ActualCassandraOct 24, 2023Copper Contributor
Thanks - we do have a ticket, but the help has been ... less than useful so I have posted over here, too.
- Oct 24, 2023
ActualCassandra I suggest opening a ticket with Microsoft security team so they can check your tenant in backend with MDE because your devices are triggering alerts for processes related to the windows and that abnormal.
- ActualCassandraOct 24, 2023Copper Contributor
elieelkarkafi
I can install one - we have multiple boxes with different configs kicking out these weird incidents.