Forum Discussion
Dean_Gross
May 26, 2022Silver Contributor
Investigation Status - Unsupported Alert Type from MDCA
What does in mean when an alert from MDCA shows up as an Unsupported Alert Type
- May 27, 2022Hi Dean, this means that our AutoIR can't pick-up the alert to do an automated investigation. For some alerts we don't have a playbook (yet)
john1263
Aug 16, 2022Copper Contributor
HeikeRitter Hi Ms Ritter
Silly question.
Does that mean the AutoIR capability works in general but just doesnt work for any IPs indicated in IOCs?
HeikeRitter
Microsoft
Aug 16, 2022There is no such things as silly questions! 🙂
No, it means it can't handle certain alert TYPES, but it doesn't mean that it can't investigate and remediate IP related alerts.
No, it means it can't handle certain alert TYPES, but it doesn't mean that it can't investigate and remediate IP related alerts.