Forum Discussion
Dean_Gross
May 26, 2022Silver Contributor
Investigation Status - Unsupported Alert Type from MDCA
What does in mean when an alert from MDCA shows up as an Unsupported Alert Type
- May 27, 2022Hi Dean, this means that our AutoIR can't pick-up the alert to do an automated investigation. For some alerts we don't have a playbook (yet)
HeikeRitter
Microsoft
May 27, 2022Hi Dean, this means that our AutoIR can't pick-up the alert to do an automated investigation. For some alerts we don't have a playbook (yet)
- Jason0903Jan 26, 2023Copper Contributor
Hi, is there any playbook for this yet?
What does it mean when an alert from MDE shows up as an Unsupported Alert Type - john1263Aug 16, 2022Copper Contributor
HeikeRitter Hi Ms Ritter
Silly question.
Does that mean the AutoIR capability works in general but just doesnt work for any IPs indicated in IOCs?
- HeikeRitterAug 16, 2022
Microsoft
There is no such things as silly questions! 🙂
No, it means it can't handle certain alert TYPES, but it doesn't mean that it can't investigate and remediate IP related alerts.
- Dean_GrossMay 27, 2022Silver Contributorthanks, it would be helpful if that was documented somewhere.
- HeikeRitterMay 27, 2022
Microsoft
Thanks Dean; I've requested that update to the doc page and it will be added. Thanks again!