Forum Discussion
ActualCassandra
Oct 23, 2023Copper Contributor
MDE repeatable false positive "Multi-stage incident involving Privilege escalation..." How to fix?
Anyone else seeing this? It always has 57 alerts, too, and the Detection source is always 'Custom TI' and always at the same time in the morning. Doesn't matter if the machine is managed, AD joined, ...
ActualCassandra
Oct 31, 2023Copper Contributor
OK, this happens every seven days at the exact same time, when Windows 10 is carrying out its behind the scenes operating system scheduled tasks. Example (similar to the original screenshot):
Oct 31, 2023
ActualCassandra you dont have any custom indicators in your MDE settings ?
- MaheshMarthiNov 15, 2023MCTmake sure you have access to existing TI projects. While creating a new one , it shows "accessible to Me" option.
- MaheshMarthiNov 15, 2023MCTThere is a section called Threat Intelligence. if you dont find it, try going to
https://ti.defender.microsoft.com/projects?tab=team - ActualCassandraNov 01, 2023Copper ContributorNo, that is what makes it so strange. I have even used the API to list indicators and there is nothing there to trigger something like the incident above.