MDR Finding [CHK-3035]
This ticket is opened by Attic MDR when our analysts or the MDR pipeline find something on your tenant that is worth telling you about, but that does not fall into one of the specific categories Attic reports on separately.
Most MDR findings have a template of their own: a web shell, a ransomware family, a credential-theft tool. Those produce their own ticket type with their own guidance. This ticket is the catch-all for everything else — a one-off observation, an unusual combination of events, or a finding that does not fit a named pattern.
Because it is a catch-all, the important content is in the ticket itself rather than in this article. The MDR pipeline writes the body per finding, so the ticket tells you what was observed, what Attic already did about it, and what we recommend you do next.
Rationale
Detection content never covers everything. A pattern that has not been seen before, a combination of weak signals that only matters together, or an observation an analyst makes while reviewing something else — none of these fit a pre-written template, and all of them can matter.
Rather than discard those findings or force them into a category that does not describe them, Attic MDR reports them as they are. That keeps the specific ticket types precise: when you receive a ransomware ticket, it really is a ransomware family, because the borderline cases are not being pushed into it to make them fit somewhere.
The trade-off is that this ticket type carries less predictable content than the others. Treat the severity and the written recommendation in the ticket as the guide, not the ticket type itself.