Forum Discussion

Slawomir_Smolarczyk's avatar
Slawomir_Smolarczyk
Copper Contributor
Jan 29, 2024

AttackTechniques missing in AlertInfo?

Does anyone know if it's a normal behavior that AttackTechniques is missing from AlertInfo, or is it some kind of bug?

According to https://learn.microsoft.com/en-us/microsoft-365/security/defender/advanced-hunting-alertinfo-table?view=o365-worldwide

"AttackTechniques: MITRE ATT&CK techniques associated with the activity that triggered the alert"

(I guess from here https://attack.mitre.org/

Will AttackTechniques in AlertInfo always match the same in AlertEvidence and the empty field in the example above can simply be ignored?

No RepliesBe the first to reply