▲ 1 r/DefenderATP
False Positives in DisruptionAndResponseEvents schema?
Hi Guys,
Last week we received multiple alerts (>100 alerts) with "Lateral movement using remote logon by contained user blocked"
I already checked several times for different logontypes, SMB, RDP, RPC, etc. events and found no suspicious behavior on our environment.
Then, apparently just within the same day I discovered that there seem to be a new schema under ATH "DisruptionAndResponseEvents". The alerts I received was the entry under this schema for the past 30days.
Is this most likely a False Positive and have you guys experienced this on your end too?
Would appreciate any insights on this guys.
u/LadyJohn21 — 9 days ago