Forum Discussion

agattsek's avatar
agattsek
Copper Contributor
Jul 29, 2020

MDATP KQL Query isolated machines

How would you write the Hunting query to identify machiens that have been isolated via MDATP?

 

Thanks,

 

Andrew

 

  • Good morning agattsek ,

    I can validate that isolate and unisolate are listed on the timeline, but I was unable to find those specific events within advanced hunting today.

    I tried to find something in the timeline that corresponded with the isolation event (i.e. a process launch or whatnot), but was unable to find a reliable indicator.

    • agattsek's avatar
      agattsek
      Copper Contributor

      MichaelJMelone

      Is this something that would better be suited for say Sentinel or MCAS regarding the ability to perform a query such as this? 

      • MichaelJMelone's avatar
        MichaelJMelone
        Icon for Microsoft rankMicrosoft

        agattsek Defender ATP \ MTP is definitely the right place to show isolation information in my opinion. This may be an example of whitespace - an area where we need to improve. Tali Ash for visibility \ comment.

  • We are looking at ingesting this data into advanced hunting as well.
    • agattsek's avatar
      agattsek
      Copper Contributor

      Please provide an update should the query language be identified, tested, and proven to produce the desired results. Thank you! Tali Ash 

    • nfmiringu's avatar
      nfmiringu
      Copper Contributor

      Tali Ash Hello, was this implemented? I checked the DeviceInfo and DeviceEvents tables (thinking these would have info on whether a device is isolated or not), but could not see anything to do with isolation. I suggest adding a bool column/attribute in the DeviceInfo table with the name 'IsIsolated', or adding isolation info in the existing 'MitigationStatus' or 'AdditionalFields' attributes.

       

      Alternatively, where can I submit a feature request for this if needed?

       

      Thanks 🙂 

Resources