@@ -600,8 +600,6 @@ The following tables include the Defender for Servers security alerts [to be dep
600
600
601
601
| ** Alert Type** | ** Alert Display Name** | ** Severity**
602
602
| ---| ---| ---|
603
- VM.Windows_KnownCredentialAccessTools | Suspicious process executed | High
604
- VM.Windows_SuspiciousAccountCreation | Suspicious Account Creation Detected | Medium
605
603
VM_AbnormalDaemonTermination | Abnormal Termination | Low
606
604
VM_BinaryGeneratedFromCommandLine | Suspicious binary detected | Medium
607
605
VM_CommandlineSuspectDomain Suspicious | domain name reference | Low
@@ -700,6 +698,7 @@ VM.Windows_ExecutableDecodedUsingCertutil | Detected decoding of an executable u
700
698
VM.Windows_FileDeletionIsSospisiousLocation | Suspicious file deletion detected | Medium
701
699
VM.Windows_KerberosGoldenTicketAttack | Suspected Kerberos Golden Ticket attack parameters observed | Medium
702
700
VM.Windows_KeygenToolKnownProcessName | Detected possible execution of keygen executable Suspicious process executed | Medium
701
+ VM.Windows_KnownCredentialAccessTools | Suspicious process executed | High
703
702
VM.Windows_KnownSuspiciousPowerShellScript | Suspicious use of PowerShell detected | High
704
703
VM.Windows_KnownSuspiciousSoftwareInstallation | High risk software detected | Medium
705
704
VM.Windows_MsHtaAndPowerShellCombination | Detected suspicious combination of HTA and PowerShell | Medium
@@ -713,6 +712,7 @@ VM.Windows_RansomwareIndication | Ransomware indicators detected | High
713
712
VM.Windows_SqlDumperUsedSuspiciously | Possible credential dumping detected [ seen multiple times] | Medium
714
713
VM.Windows_StopCriticalServices | Detected the disabling of critical services | Medium
715
714
VM.Windows_SubvertingAccessibilityBinary | Sticky keys attack detected <br /> Suspicious account creation detected Medium
715
+ VM.Windows_SuspiciousAccountCreation | Suspicious Account Creation Detected | Medium
716
716
VM.Windows_SuspiciousFirewallRuleAdded | Detected suspicious new firewall rule | Medium
717
717
VM.Windows_SuspiciousFTPSSwitchUsage | Detected suspicious use of FTP -s switch | Medium
718
718
VM.Windows_SuspiciousSQLActivity | Suspicious SQL activity | Medium
0 commit comments