Forum Discussion

Bram_InSpark's avatar
Bram_InSpark
Copper Contributor
Oct 29, 2019

Cloud Discovery | Total amount of traffic

Dear community members,

 

we're using Microsoft Defender ATP to collect machine data in the Cloud Discovery dashboard of Microsoft Cloud App Security. Does anyone know how accurate the upload traffic is within the discovered apps overview? Below some details:

 

- User uploads 2 files to WeTransfer on endpoint level, which is onboarded into MDATP;

- User is not behind a proxy;

- Last data received field from MDATP is updated;

- Cloud Discovery doesn't show any upload traffic and no updates in the WeTransfer statistics.

 

I'm very curious how this works.

 

Kind regards,

Bram

3 Replies

  • Hi Bram,

    Do you have any details about the size of the files that were uploaded by the user to WeTransfer?

    Thanks,
    Danny.
    • Bram_InSpark's avatar
      Bram_InSpark
      Copper Contributor

      Danny Kadyshevitch

      Hi Danny,

      thanks for answering, sorry for my late response, I didn't noticed the alert for a new answer. So we used a file of 1GB and later a file of 512 MB to upload to WeTransfer. Later on we downloaded both files by using the MDATP connected W10 device and the logged on corporate user account so we were sure that the traffic details would be collected by MDATP/MCAS. The upload and download details are not updated in MCAS. The specific user is not behind a proxy. 

       

      Kind regards,

      Bram

      • Danny Kadyshevitch's avatar
        Danny Kadyshevitch
        Former Employee

        Hi Bram_InSpark.

         

        While investigating this, I would be happy to know if you got to check in MDATP portal whether there was any traffic going to wetransfer.com captured in machine's timeline?

         

        Thanks.