Skip to content

Commit 7d12e5b

Browse files
Merge pull request #272590 from dcurwin/wi-245361-fileless-alerts-april18-2024
Fileless attack alerts deprecation
2 parents a436949 + 4812710 commit 7d12e5b

File tree

1 file changed

+20
-0
lines changed

1 file changed

+20
-0
lines changed

articles/defender-for-cloud/upcoming-changes.md

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -25,6 +25,7 @@ If you're looking for the latest release notes, you can find them in the [What's
2525

2626
| Planned change | Announcement date | Estimated date for change |
2727
|--|--|--|
28+
| [Deprecation of fileless attack alerts](#deprecation-of-fileless-attack-alerts) | April 18, 2024 | May 2024 |
2829
| [Change in CIEM assessment IDs](#change-in-ciem-assessment-ids) | April 16.2024 | May 2024 |
2930
| [Deprecation of encryption recommendation](#deprecation-of-encryption-recommendation) | April 3, 2024 | May 2024 |
3031
| [Deprecating of virtual machine recommendation](#deprecating-of-virtual-machine-recommendation) | April 2, 2024 | April 30, 2024 |
@@ -46,6 +47,25 @@ If you're looking for the latest release notes, you can find them in the [What's
4647
| [Deprecating two security incidents](#deprecating-two-security-incidents) | | November 2023 |
4748
| [Defender for Cloud plan and strategy for the Log Analytics agent deprecation](#defender-for-cloud-plan-and-strategy-for-the-log-analytics-agent-deprecation) | | August 2024 |
4849

50+
## Deprecation of fileless attack alerts
51+
52+
**Announcement date: April 18, 2024**
53+
54+
**Estimated date for change: May 2024**
55+
56+
In May 2024, to enhance the quality of security alerts for Defender for Servers, the fileless attack alerts specific to Windows and Linux virtual machines will be discontinued. These alerts will instead be generated by Defender for Endpoint:
57+
58+
- Fileless attack toolkit detected (VM_FilelessAttackToolkit.Windows)
59+
- Fileless attack technique detected (VM_FilelessAttackTechnique.Windows)
60+
- Fileless attack behavior detected (VM_FilelessAttackBehavior.Windows)
61+
- Fileless Attack Toolkit Detected (VM_FilelessAttackToolkit.Linux)
62+
- Fileless Attack Technique Detected (VM_FilelessAttackTechnique.Linux)
63+
- Fileless Attack Behavior Detected (VM_FilelessAttackBehavior.Linux)
64+
65+
All security scenarios covered by the deprecated alerts are fully covered Defender for Endpoint threat alerts.
66+
67+
If you already have the Defender for Endpoint integration enabled, there's no action required on your part. In May 2024 you might experience a decrease in your alerts volume, but still remain protected. If you don't currently have Defender for Endpoint integration enabled in Defender for Servers, you need to enable integration to maintain and improve your alert coverage. All Defender for Server customers can access the full value of Defender for Endpoint's integration at no additional cost. For more information, see [Enable Defender for Endpoint integration](enable-defender-for-endpoint.md).
68+
4969
## Change in CIEM assessment IDs
5070

5171
**Announcement date: April 16, 2024**

0 commit comments

Comments
 (0)