Jun 13 2020 04:30 PM
We have a regular vulnerability scan against the workstations and it keeps triggering incidents as it trying to login with known, easy to guess, passwords. Is there a way to whitelist connections from a private IP so we don't MDATP alerts during scans?
Jun 13 2020 05:16 PM
I should also mention that this scan triggers an "Internal brute-force attack" incident that doesn't have an IOC attached to it so it is not possible to create a suppression rule. Since this is an internal IP, I cannot add it to the list of custom IOCs either (though not sure how would that help if the incident doesn't include it as an IOC).
The best I can do is to suppress this type of alert completely but that would leave the computers open to real internal brute-force attacks.
Jul 20 2020 11:08 AM