May 02 2018 04:46 AM - edited May 02 2018 04:49 AM
I may be in the wrong place but we have had a malware message coming from azure office 365 and as its going into our SIEM people are asking why we aren't getting alerts .
Well the simple answer is ..NO other threat intelligence is registering this one .. alien vault cymon Ibm threat exchange.
So can we ask azure to check this again as I am having to tell people that only Microsoft rate this as a threat when it looks like a talktalk ip address
The suspect ip is 78.146.59.105
Steve
May 03 2018 04:31 AM
Hi Stephen,
This is indeed not the right place. I would like to suggest to contact Microsoft support: https://support.microsoft.com/en-gb
Best regards,
Mark