Share via

Microsoft Defender Alert for Suspicious Network Traffic from Specific IP Address

Anonymous
2025-01-19T12:17:15+00:00

Dear Microsoft Support Team,

I am seeking assistance regarding a security alert generated by Microsoft Defender on my internet-facing SFTP server. The alert pertains to suspicious network traffic originating from a specific IP address. Despite reviewing the available logs and utilizing our SIEM system, I have been unable to gather detailed information about this activity.

Details:

  • Alert Type: Suspicious network traffic detected by Microsoft Defender
  • Server Role: Internet-facing SFTP server
  • Observations:
    • Multiple unauthorized SSH connection attempts from various IP addresses
    • Defender flagged only the specified IP address for suspicious activity
    • Limited information available in both Defender and our SIEM system regarding this alert

I would appreciate your assistance in understanding the following:

  1. Reason for Alert Specificity: Why did Microsoft Defender flag only this particular IP address among the numerous unauthorized connection attempts from multiple malicious IPs?
  2. Recommended Actions: What steps should I take to further investigate and mitigate potential threats from this IP address?

Your guidance will be instrumental in enhancing the security of our SFTP server and ensuring appropriate measures are implemented to address potential threats.

Thank you for your support.

Microsoft 365 and Office | Microsoft 365 Defender | Other | Other

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

1 answer

Sort by: Most helpful
  1. Anonymous
    2025-01-21T09:54:46+00:00

    Hello CyberSec_96.

    Welcome to the Microsoft Community.

    Thank you for choosing Microsoft Defender to help optimize your security. Since we primarily assist personal and home users, when it comes to advanced applications of Microsoft Defender, our experience may not be applicable.

    We recommend posting in a dedicated community for more specialized assistance: Microsoft Defender for Cloud Apps - Microsoft Q&A

    Users or experts familiar with Microsoft Defender can provide you with professional advice!

    We hope these steps help resolve your issue.

    Best Regards,

    Eliac | Microsoft Community Support Specialist

    0 comments No comments