ATA & Win10

%3CLINGO-SUB%20id%3D%22lingo-sub-237812%22%20slang%3D%22en-US%22%3EATA%20%26amp%3B%20Win10%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-237812%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3EIs%20there%20any%20known%20issues%20with%20Win10%20stations%20%26amp%3B%20f%2Fp%20alerts%20on%26nbsp%3B%22Reconnaissance%20using%20Directory%20Services%20queries%26nbsp%3B%3F%3C%2FP%3E%3CP%3EI%20know%20about%20the%26nbsp%3B%3CSPAN%3E%26nbsp%3BCIFS%20(445%2Ftcp)%26nbsp%3B%E2%80%9CSuspicion%20of%20identity%20theft%20based%20on%20abnormal%20behavior%E2%80%9D%20and%20Win10%26nbsp%3BWUDO..%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3E10x%2C%20Haim.%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-237812%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAdvanced%20Threat%20Analytics%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EWindow%2010%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-237819%22%20slang%3D%22en-US%22%3ERe%3A%20ATA%20%26amp%3B%20Win10%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-237819%22%20slang%3D%22en-US%22%3EWhy%20do%20machines%20generate%20SAMR%20queries%20%3F%20which%20process%20initiate%20it%20%3F%3CBR%20%2F%3EI%20think%20learning%20period%20is%20quite%20over%20because%20ATA%20is%20present%20for%20almost%20two%20years..%3CBR%20%2F%3EGonna%20check%20if%20Lenovo%20is%20relevant.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-237817%22%20slang%3D%22en-US%22%3ERe%3A%20ATA%20%26amp%3B%20Win10%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-237817%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Haim%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThere%20are%20a%20lot%20of%20machines%20that%20generate%20SAMR%20queries%2C%20therefore%20we%20have%20a%20learning%20period%20to%20learn%20the%20normal%20behavior.%20I%20guess%20that%20in%20a%20few%20weeks%20from%20now%20after%20we%20will%20learn%20it%20behavior%20we%20will%20stop%20alert.%20If%20you%20are%20sure%20it%20is%20FP%20you%20can%20Suppress%20the%20alert.%3C%2FP%3E%0A%3CP%3EWhich%20devices%20are%20they%3F%20Lenovo%3F%20We%20know%20that%20Lenovo%20devices%20might%20generate%20SAMR%20queries%20and%20cause%20FP%20until%20we%20learn%20it.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThanks%2C%3C%2FP%3E%0A%3CP%3ETali%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-237816%22%20slang%3D%22en-US%22%3ERe%3A%20ATA%20%26amp%3B%20Win10%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-237816%22%20slang%3D%22en-US%22%3EHi%20Tali%2C%3CBR%20%2F%3E%3CBR%20%2F%3EWe%20have%20numerous%20%22Reconnaissance%20using%20Directory%20Services%20queries%22%20from%20different%20Win10%20%3A%3CBR%20%2F%3E%3CBR%20%2F%3EWindows%2010%20Pro%2C%2010.0%20(16299)%3CBR%20%2F%3EWindows%2010%20Pro%2C%2010.0%20(15063)%3CBR%20%2F%3EWindows%2010%20Pro%2C%2010.0%20(10586)%3CBR%20%2F%3EWindows%2010%20Pro%2C%2010.0%20(14393)%3CBR%20%2F%3E%3CBR%20%2F%3ESome%20started%20just%20after%20the%20computer%20was%20installed%20via%20corporate%20image.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-237815%22%20slang%3D%22en-US%22%3ERe%3A%20ATA%20%26amp%3B%20Win10%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-237815%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Tali%2C%3C%2FP%3E%3CP%3EWe%20have%20numerous%20%3CSPAN%20class%3D%22ng-binding%22%3E%22Reconnaissance%20using%20Directory%20Services%20queries%22%20from%20different%20Win10%20%3A%3C%2FSPAN%3E%3C%2FP%3E%3CDIV%20class%3D%22entityInformationId%22%3E%3CDIV%20class%3D%22entityInformationIdTitleContainer%22%3E%3CDIV%20class%3D%22entityInformationIdTitle%20ellipsis%20ng-scope%20ng-isolate-scope%22%3E%3CDIV%20class%3D%22ellipsisText%22%3E%3CSPAN%3EWindows%2010%20Pro%2C%2010.0%20(16299)%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%20class%3D%22ellipsisText%22%3E%3CDIV%20class%3D%22entityInformationId%22%3E%3CDIV%20class%3D%22entityInformationIdTitleContainer%22%3E%3CDIV%20class%3D%22entityInformationIdTitle%20ellipsis%20ng-scope%20ng-isolate-scope%22%3E%3CDIV%20class%3D%22ellipsisText%22%3E%3CDIV%20class%3D%22entityInformationId%22%3E%3CDIV%20class%3D%22entityInformationIdTitleContainer%22%3E%3CDIV%20class%3D%22entityInformationIdTitle%20ellipsis%20ng-scope%20ng-isolate-scope%22%3E%3CDIV%20class%3D%22ellipsisText%22%3E%3CSPAN%3EWindows%2010%20Pro%2C%2010.0%20(15063)%3C%2FSPAN%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3CDIV%20class%3D%22ellipsisText%22%3E%3CDIV%20class%3D%22entityInformationId%22%3E%3CDIV%20class%3D%22entityInformationIdTitleContainer%22%3E%3CDIV%20class%3D%22entityInformationIdTitle%20ellipsis%20ng-scope%20ng-isolate-scope%22%3E%3CDIV%20class%3D%22ellipsisText%22%3E%3CSPAN%3EWindows%2010%20Pro%2C%2010.0%20(10586)%3C%2FSPAN%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3CDIV%20class%3D%22ellipsisText%22%3E%3CDIV%20class%3D%22entityInformationId%22%3E%3CDIV%20class%3D%22entityInformationIdTitleContainer%22%3E%3CDIV%20class%3D%22entityInformationIdTitle%20ellipsis%20ng-scope%20ng-isolate-scope%22%3E%3CDIV%20class%3D%22ellipsisText%22%3E%3CSPAN%3EWindows%2010%20Pro%2C%2010.0%20(14393)%3C%2FSPAN%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3CDIV%20class%3D%22entityInformationStates%20ng-isolate-scope%22%3E%3CDIV%20class%3D%22entityInformationId%22%3E%3CDIV%20class%3D%22entityInformationIdTitleContainer%22%3E%3CDIV%20class%3D%22entityInformationIdTitle%20ellipsis%20ng-scope%20ng-isolate-scope%22%3E%3CDIV%20class%3D%22ellipsisText%22%3E%26nbsp%3B%3C%2FDIV%3E%3CDIV%20class%3D%22ellipsisText%22%3E%3CSPAN%3ESome%20started%20just%20after%20the%20computer%20was%20installed%20via%20corporate%20image.%3C%2FSPAN%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3CDIV%20class%3D%22entityInformationStates%20ng-isolate-scope%22%3E%26nbsp%3B%3C%2FDIV%3E%3CDIV%20class%3D%22entityInformationFields%22%3E%26nbsp%3B%3C%2FDIV%3E%3C%2FDIV%3E%3CDIV%20class%3D%22suspiciousActivityProfileTopContentDescription%22%3E%3CDIV%20class%3D%22suspiciousActivityDescription%22%3E%3CDIV%20class%3D%22entities%20ng-isolate-scope%22%3E%26nbsp%3B%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-237814%22%20slang%3D%22en-US%22%3ERe%3A%20ATA%20%26amp%3B%20Win10%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-237814%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Haim%2C%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThere%20is%20no%20known%20issue%20with%20Win10.%20What%26nbsp%3Bdo%20you%20experience%3F%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThanks%2C%3C%2FP%3E%0A%3CP%3ETali%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

Hi,

Is there any known issues with Win10 stations & f/p alerts on "Reconnaissance using Directory Services queries ?

I know about the  CIFS (445/tcp) “Suspicion of identity theft based on abnormal behavior” and Win10 WUDO..

 

10x, Haim.

5 Replies

Hi Haim, 

 

There is no known issue with Win10. What do you experience?

 

Thanks,

Tali

Hi Tali,

We have numerous "Reconnaissance using Directory Services queries" from different Win10 :

Windows 10 Pro, 10.0 (16299)
Windows 10 Pro, 10.0 (15063)
Windows 10 Pro, 10.0 (10586)
Windows 10 Pro, 10.0 (14393)
 
Some started just after the computer was installed via corporate image.
 
 
 
Hi Tali,

We have numerous "Reconnaissance using Directory Services queries" from different Win10 :

Windows 10 Pro, 10.0 (16299)
Windows 10 Pro, 10.0 (15063)
Windows 10 Pro, 10.0 (10586)
Windows 10 Pro, 10.0 (14393)

Some started just after the computer was installed via corporate image.

Hi Haim,

 

There are a lot of machines that generate SAMR queries, therefore we have a learning period to learn the normal behavior. I guess that in a few weeks from now after we will learn it behavior we will stop alert. If you are sure it is FP you can Suppress the alert.

Which devices are they? Lenovo? We know that Lenovo devices might generate SAMR queries and cause FP until we learn it.

 

Thanks,

Tali

Why do machines generate SAMR queries ? which process initiate it ?
I think learning period is quite over because ATA is present for almost two years..
Gonna check if Lenovo is relevant.