Two Microsoft Defender for Identity Alerts Missing Content

Anonymous
2022-05-12T20:14:09.667+00:00

Hello,

Two Defender for Identity alerts that we get regularly come in with almost no information. We believe there is something wrong with the sensor but don't have visibility on it.

  1. Account enumeration reconnaissance (on one endpoint)
  2. remote code execution (on one endpoint)

Does anyone know what needs to be tweaked in order to enrich these alerts? It's been quite challenging to address them. Thank you!

201612-account-enumeration-reconnaissance.png201631-remote-code-execution.png

Microsoft Security | Microsoft Sentinel
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.