Microsoft Defender is generating event after wmic os get Caption - how to tune it?

aaz-uzso (Sadowski, Lukasz) 1 Reputation point
2022-02-10T12:15:29.62+00:00

Hello,
Is there any way to tune running this command: wmic os get Caption?

Some users from our company are using tools which finally are running this command we are having event
"Suspicious sequence of exploitation activities" in Microsoft Defender.

Can we tune it somehow?

Best Regards,
Łukasz Sadowski

Microsoft Graph
Microsoft Graph
A Microsoft programmability model that exposes REST APIs and client libraries to access data on Microsoft 365 services.
11,447 questions
0 comments No comments
{count} votes