Forum Discussion

Jean-Philippe Breton's avatar
Jean-Philippe Breton
Iron Contributor
Nov 26, 2021

Question about testing SpyShelter

We are currently building a PoC for a customer.

We are about 100 Windows 10 onboard into MDE.

 

Customer is in healthcare thus many users have local Admin privilege.

 

During a test phase, customer was able to run https://www.spyshelter.com/security-test-tool/

Keylogging could run

Registry entry modification could run

Many other stuff could run

 

Nothing came up in MDE Alerts.

Can someone explain why no alert 

5 Replies

  • mas18's avatar
    mas18
    Brass Contributor
    Do you have any other endpoint protection solution also running in the Machine ? If you have other endpoint protection running as primary then you may need to enable EDR in Block mode but you will have limited edr capabilities while running defender in passive mode.
    • Jean-Philippe Breton's avatar
      Jean-Philippe Breton
      Iron Contributor
      No other Endpoint, except the MDE stack (Defender AV/ SmartScreen)
      Pure Microsoft
      No passive mode.
      EDR in Block Mode is also enable.
      • mas18's avatar
        mas18
        Brass Contributor
        Does events are coming in device timeline ?does mde client analyser tool results shows any connectivity issue between client and mde cloud?