Forum Discussion

dfejag's avatar
dfejag
Copper Contributor
Jul 22, 2020

Not all Alerts in mcas are sent on to the siem

Hi all

 

We have connected mcas to our siem using the siem agent/token. We receive Alerts and Activity data. However not all Alerts I can see in mcas Alerts page can be found in the siem.

 

None of the Azure ATP alerts that show in mcas (i.e. Suspected DCSync attack (replication of directory services) or Remote code execution attempt) can be found in the siem.

 

We had hoped to use mcas as a broker for M365 ATP services like AATP, O365ATP etc. Is this possible? Thanks
J

Resources