High-Severity Incident Under Analyst Review [CHK-3020]
This ticket covers a high-severity Microsoft Defender incident on your tenant that had no automatic remediation available, and that Attic MDR routed for analysis.
Attic MDR handles incoming Defender incidents in two stages. L1 ingests and filters. For each incident it reaches one of four conclusions: raise a ticket directly, drop it, send it for analysis, or raise a ticket directly and send it for analysis as well. L2 is where that analysis happens, and where IVON, the Attic analyst behind our MDR service, works.
A ticket of this type means the incident went to L2, so IVON analysed it. Her findings and any recommended action are written into the ticket.
The ticket may look almost empty when it first appears. Where an incident is sent for analysis, the ticket is registered up front so there is a record of it from the start. The content arrives once IVON has finished. An empty ticket is not a mistake; it means the analysis is still running.
Rationale
High severity with no automatic remediation is, by definition, something the tooling could not resolve on its own. That combination is exactly what warrants analysis rather than a raw alert forwarded straight to you.
A high-severity rating reflects Microsoft's assessment of the technique in isolation, not what it means in your environment. Analysis is what supplies the missing half: whether the activity fits your organisation, whether it connects to anything else, and what you should actually do about it.
IVON can escalate an incident to a human analyst at Attic. That does not happen on every incident. It depends on how confident she is in her own analysis and on the quality checks run against it, so escalation reflects a genuine need for a second pair of eyes rather than a routine step.
Follow-up
Follow these steps to adequately handle this ticket:
- If the ticket is empty, wait. The analysis is still in progress and the ticket will be filled in when it completes.
- Read the analysis. What was found, and any recommended action, is specific to this incident and takes precedence over the general guidance here.
- Act on the recommendation rather than on the raw severity. A high-severity label draws attention, but the analysis is what establishes whether this matters in your environment. If action is needed, the ticket says so and says what.
- Answer any question the ticket asks. Whether activity was expected is the most common thing that cannot be settled from the data alone: a project, a new tool, a scheduled task, an administrator working late. A quick answer is usually what closes the incident fastest.
- Act immediately if the incident has been escalated. Where the analysis warrants it, a human analyst at Attic picks the incident up and the ticket is updated with containment steps. Treat it with the urgency of the confirmed finding.