Skip to content
English
  • There are no suggestions because the search field is empty.

Low-Severity Incident Analysis [CHK-3024]

This ticket covers a low-severity Microsoft Defender incident on your tenant that had no automatic remediation available, and that Attic MDR routed for analysis.

Attic MDR handles incoming Defender incidents in two stages. L1 ingests and filters, deciding whether an incident is ticketed directly, dropped, sent for analysis, or both ticketed and analysed. L2 is where the analysis happens, and where IVON, the Attic analyst behind our MDR service, works. This ticket means the incident reached L2 and IVON analysed it.

In most cases no action is required from you. The ticket exists so that you can see what was analysed and what came of it. It may look almost empty at first, because incidents sent for analysis have their ticket registered up front and the content arrives when IVON has finished.

Rationale

Low-severity incidents are the background noise of a monitored environment: a blocked file, an unusual but explainable process, a policy triggering as designed. The great majority are exactly what they appear to be.

They are still analysed rather than discarded, for two reasons. Severity is assigned by Microsoft based on the technique in isolation, without knowing your environment, so something rated low can matter more in context, particularly on a server or a privileged account. And low-severity events are where a careful attacker prefers to operate, precisely because the rating discourages anyone from looking.

Escalation from here is rare. IVON raises an incident to a human analyst at Attic when her confidence or the quality checks against her analysis call for it, and at this severity that is uncommon. The point of analysing anyway is that the decision is made on what the event turns out to be, not on the label it arrived with.

Follow-up

Follow these steps to adequately handle this ticket:

  1. No action is normally required. Unless the ticket explicitly asks something of you, this is the record of an analysis rather than a request.
  2. If the ticket is empty, the analysis is still running. The content is added when it completes.
  3. Answer any question the ticket asks. Occasionally a low-severity incident needs one piece of context you have and the data does not: whether a device is expected to behave that way, or whether a user was doing something unusual but legitimate.
  4. Act if the incident has been escalated. Low-severity incidents occasionally turn out to be one visible part of something larger. Where the analysis establishes that, a human analyst at Attic picks it up, the ticket is updated, and the urgency changes with it.

More information