Duplicate Alerts from Custom Detections in Advanced Hunting

Hi all,

Was hoping someone could help me figure out why I keep getting duplicate alerts for my custom detections.

When I create them and run them, I get 1 alert. However, when they auto-run, they will send me 1 of the same alert, every hour, for the next few hours. Im assuming its something to do with the Frequency + Lookback.

For example, I look for something in the table EmailEvents. Then, it triggers at 10am - 1 alert - Perfect.

However, that same alert will trigger again at 11am, 12pm, and 1pm.

I have been doing 1 hour frequency and 4 hour lookback. Am i supposed to make them equal? How do I make the alerts not duplicate the same alert every hour?

reddit.com
u/Cant_Think_Name12 — 8 days ago

Same Songs on Repeat...

Hi all,

I keep getting the same songs and artists on repeat and im not sure why.. I

I have cleared all the data on the app, created playlists, i make mixes off those playlists.. The songs are all the same on repeat from my playlist, or just the same 5 artists on repeat. I went through and chose artists that i liked - but its not playing those artists either.

If I go to any of the Ai-Generated playlists for me (or my supermix ) - its only unknown, terrible artists ive never heard of, with the occasional artists ive heard of - but, repeating the same songs i keep skipping..

Any way to fix this? I'm going nuts listening to the same 5 artists and a million unknown artists.

reddit.com
u/Cant_Think_Name12 — 1 month ago

Disable Alert Correlation/Grouping - Custom XDR Alerts?

Hi All,

Is there a way to disable alert grouping or alert correlation for XDR custom alerts? It keeps screwing up our response time for mail-bombing alerts.

For example, i have a detection rule that looks for fake-IT-Support attempts via Teams. It works flawlessly and runs continuously.

The issue is that when it triggers, it gets auto-correlated to the MS Built-in detection rule for 'Mail Bombing Activity Detected' and 'Potentially malicious IT support Teams impersonation post mail bombing'

My Custom detection either triggers well before the MS one did, or, it triggers after, but gets correlated to the MS ticket. I want a separate notification for my custom - 'Potentially malicious IT support Teams impersonation post mail bombing'. However, my custom alert keeps getting tied in with the MS-Alert, therefore, not notifying us as it should. Is there a way to bypass this?

I read this article - Manage analytics rule correlation settings in Microsoft Defender XDR - Microsoft Defender XDR | Microsoft Learn and I tried adding 'Dont_CORR' to the beginning of the Description, but it still correlated.

u/Cant_Think_Name12 — 3 months ago

'Teams Sender' Missing from TABL - Occasionally

Hi All,

I have been trying to block teams senders within XDR > TABL. The issue is that sometimes the option for 'Teams Senders' is there, and other times it is not. I confirmed with Microsoft that my tenant is configured correctly. Is anyone else experiencing the same issue?

The issue seems to arise if I don't fully sign out of XDR fully, then sign back in (that sometimes fixes it, not always). If I reuse a session from yesterday, then, Defender removes 'Teams Sender' and other settings until i fully log out.

Note: The setting (Teams Senders) seems to disappear shortly after logging in from a fresh session, and wont persist for my full session.

I have had a ticket in for 6 months about this now, and there has been ZERO movement on fixing it. Yet again, signing out and in only sometimes fixes it. We keep getting slammed by Fake Teams senders and cannot block them since the option is missing.

What it should look like:

https://preview.redd.it/vhjsq44h8h2h1.png?width=859&format=png&auto=webp&s=af60592b9a944296d16757eb31d6694786fe3ec6

What it looks like 99% of the time (Note the missing last option)

https://preview.redd.it/myssb8fj8h2h1.png?width=829&format=png&auto=webp&s=1efa56c00986e78dfc671614b8b52dd0e7123d91

My question - has anyone else experienced this? If not, can anyone tell me if you freshly sign in to Defender every day, or if you reuse your session from yesterday? Would also appreciate it if maybe you could reuse an old session and check for me if the setting is missing.

reddit.com
u/Cant_Think_Name12 — 3 months ago

How to Transfer files Safely from a Compromised (work) Device

Hi All,

I was hoping to get some feedback from everyone here on how to handle a compromised device we have at work. Long story short, malware ran and we need to retrieve files from the device (work ones) but aren't sure the best way to go about it.

We use Defender and I was thinking we could use live response while the device is in an isolated state, however, I dont know (yet) how many files the user needs from the device. If theres a handful, it will be quick. If it's a lot, it would take a long time.

My only other thought is to pull the drive, connect it to a fresh, off-domain computer, apply a write-block, then pull the required files onto a USB, then move those to the new (user) device.

My questions -

  • What method would be recommended of the two?
  • Is there a better method? If so, what would you suggest
  • How can i confirm the file(s) are clean once retrieved. (my biggest concern)

Any feedback would be great - thanks!

Edit:

u/Cant_Think_Name12 — 3 months ago
▲ 4 r/GIAC

GCFE - How similar to the Exam are the Book Quizzes

As the title implies, how similar to the exam are the book quizzes? I know the best way to judge your index is based on the practice tests, but, so far my index has been working pretty well for the book quizzes. Are the exam (multiple choice questions) similar to the quizzes?

reddit.com
u/Cant_Think_Name12 — 3 months ago