Forum Discussion

Kiril's avatar
Kiril
Steel Contributor
Mar 24, 2023

Tampering with Microsoft Defender for Endpoint sensor settings alert false positive?

I am currently investigating the following timeline. All of the involved binaries are part of Windows. How can I make sure, whether this is a false positive, or whether I need to dig deeper?

 

 

3 Replies

  • rahuljindal-MVP's avatar
    rahuljindal-MVP
    Bronze Contributor
    There maybe Windows processes, but they don't appear to be the point of origin. They don't appear to be false positives to me. Do you have other MDE components enabled like ASR? Also, do you have automated incident response enabled in Defender portal?
    • Kiril's avatar
      Kiril
      Steel Contributor

      rahuljindal-MVP 

      Thank you, yes both are enabled. ASR rules in Block mode and automated incident response.

       

      > they don't appear to be the point of origin.

       

      How to investigate the point of origin here?

       


      • rahuljindal-MVP's avatar
        rahuljindal-MVP
        Bronze Contributor

        The timeline ideally should give you details. Otherwise, advanced hunting queries will be the next best option for investigation. 

Resources