Forum Discussion
PJR_CDF
Mar 07, 2023Iron Contributor
Audit/Alerting on the use of Live Response
Wondering if/how people are auditing/monitoring the use of Live Response in their environments? From what I've seen so far, all actions are logged in the Action Center which is great but ideally ...
PJR_CDF
Jun 18, 2023Iron Contributor
I'm afraid not - the auditing of Live Response use remains a gap for now
- KaaamilJun 27, 2023Copper ContributorThat's a shame from microsoft.
Live response session can be used to abuse network as well ( domain admin creation on DC)
In article below its explained that Live Reponse API sessions can be audited but not sessions from Defender UI!
https://www.cloud-architekt.net/abuse-detection-live-response-tier0/