Alert Simulation using Playbook for Defender for Cloud - Unsuccessful attempt

Shah Tanveer Aziz 0 Reputation points
2023-03-07T13:41:02.5566667+00:00

I was trying to simulate the alerts in Defender for Cloud on Linux VMs using the play books shared at https://github.com/Azure/Microsoft-Defender-for-Cloud/tree/main/Simulations

https://github.com/Azure/Microsoft-Defender-for-Cloud/blob/main/Simulations/Microsoft%20Defender%20for%20cloud%20Linux%20Detections%20V3.pdf

On every step I have to troubleshoot. Also it is referencing to some snapshots which aren't present in current Azure environment now.

Anyone has tried to successfully simulate the alerts? I would like to get steps to complete the same. Currently I am stuck at the stage where on running hydra command on attacker VM gives error "does not support password authentication".

Thank you

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.