Medium-Severity Incident Analysis [CHK-3023]
This ticket covers a medium-severity Microsoft Defender incident on your tenant that had no automatic remediation available, and that Attic MDR routed for analysis.
Attic MDR handles incoming Defender incidents in two stages. L1 ingests and filters, concluding for each incident that it should be ticketed directly, dropped, sent for analysis, or ticketed directly and sent for analysis. L2 is where the analysis happens, and where IVON, the Attic analyst behind our MDR service, works.
A ticket of this type means the incident went to L2, so IVON analysed it. Her findings are written into the ticket.
The ticket may look almost empty when it first appears. Incidents sent for analysis have their ticket registered up front, and the content arrives once IVON has finished.
Rationale
Medium severity is where most real intrusions are visible before they become obvious. A high-severity alert announces itself. A medium-severity one often describes a single step in a longer sequence: an unusual process, an unexpected sign-in, a script doing something out of character. In isolation each is unremarkable, which is also why genuine activity at this level so often goes unexamined.
Sending these for analysis rather than closing them is the part of an MDR service that is easy to skip and expensive to skip. The value is in something actually working out what the event means in your environment, rather than in a queue of medium alerts nobody reads.
IVON can escalate to a human analyst at Attic, and does so when her confidence in the analysis or the quality checks against it call for it. Most medium-severity incidents do not reach that bar, and most of these tickets close without action needed. That is the expected outcome, not a sign the analysis was unnecessary.
Follow-up
Follow these steps to adequately handle this ticket:
- If the ticket is empty, wait. The analysis is still running and the ticket will be filled in when it completes.
- Read the analysis. What was found and any recommended action are specific to this incident.
- No immediate action is normally required. Unless the ticket says otherwise, this is the result of an analysis rather than a request that you do something.
- Answer any question the ticket asks. Whether activity was expected is the thing that cannot be settled from the data alone. A quick answer, that a user was travelling or that a tool was newly deployed, is very often what closes the incident.
- Act if the incident has been escalated. Where the analysis finds the activity is part of something larger, a human analyst at Attic picks it up and the ticket is updated with what was found and what to do.