u/LadyJohn21

False Positives in DisruptionAndResponseEvents schema?

Hi Guys,

Last week we received multiple alerts (>100 alerts) with "Lateral movement using remote logon by contained user blocked"

I already checked several times for different logontypes, SMB, RDP, RPC, etc. events and found no suspicious behavior on our environment.

Then, apparently just within the same day I discovered that there seem to be a new schema under ATH "DisruptionAndResponseEvents". The alerts I received was the entry under this schema for the past 30days.

Is this most likely a False Positive and have you guys experienced this on your end too?

Would appreciate any insights on this guys.

reddit.com
u/LadyJohn21 — 9 days ago