SOLVED

Investigation Status - Unsupported Alert Type from MDCA

Silver Contributor

What does in mean when an alert from MDCA shows up as an Unsupported Alert Type 

DeanGross_0-1653570447263.png

 

6 Replies
best response confirmed by VI_Migration (Silver Contributor)
Solution
Hi Dean, this means that our AutoIR can't pick-up the alert to do an automated investigation. For some alerts we don't have a playbook (yet)
thanks, it would be helpful if that was documented somewhere.
Thanks Dean; I've requested that update to the doc page and it will be added. Thanks again!

@Heike Ritter Hi Ms Ritter 

 

Silly question.

 

Does that mean the AutoIR capability works in general but just doesnt work for any IPs indicated in IOCs?

There is no such things as silly questions! :)
No, it means it can't handle certain alert TYPES, but it doesn't mean that it can't investigate and remediate IP related alerts.

Hi, is there any playbook for this yet?
What does it mean when an alert from MDE shows up as an Unsupported Alert Type

1 best response

Accepted Solutions
best response confirmed by VI_Migration (Silver Contributor)
Solution
Hi Dean, this means that our AutoIR can't pick-up the alert to do an automated investigation. For some alerts we don't have a playbook (yet)

View solution in original post