Community Center | Not monitored
Tag not monitored by Microsoft.
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
I'm looking at testing out the Deception Capability in Defender XDR, but had a question in regard to the alerting and response in the event a lure or decoy is accessed on a device. If an alert is generated as a result of a Deception Rule match, are there any automated AIR response investigations or actions taken on those devices? or is this just more of a canary/honey token type of alert?
Tag not monitored by Microsoft.
Validated and tested that these alerts do not trigger and AIR response investigation.