Aug 18 2023 12:34 AM - edited Aug 18 2023 12:37 AM
Hello All,
we have received below security alert in Microsoft defender for cloud for our App service.
1) NMap scanning detected (for this we got the carrier and organization as Microsoft)
2) Vulnerability scanner detected
3) Suspicious User Agent detected
Our website is Internet facing (Public facing). so, we cannot put much restriction on our app service (ex IP restriction, SSL certificate).
We are unable to investigate the below alerts. we checked the log analytics workspace logs but and extracted the logs from the caller IP. but could not find much information form it
we also checked there was no impact found on our webapp.
1) NMap scanning detected (for this we got the carrier and organization as Microsoft)
2) Vulnerability scanner detected
3) Suspicious User Agent detected
Is there any way by which we can investigate why these alerts got generated. and what next action can be taken on this ?
Sep 08 2023 02:33 PM