Unrecognised Incident Pattern Analysis [CHK-3022]
This ticket covers a Microsoft Defender incident on your tenant that did not fit any of the shapes Attic MDR routes on its own, and that was sent for analysis rather than being closed.
Attic MDR handles incoming Defender incidents in two stages. L1 ingests and filters, concluding for each incident that it should be ticketed directly, dropped, sent for analysis, or ticketed directly and sent for analysis. L2 is where the analysis happens, and where IVON, the Attic analyst behind our MDR service, works. This ticket means the incident reached L2 and IVON analysed it.
The ticket may look almost empty when it first appears. Incidents sent for analysis have their ticket registered up front, and the content arrives once IVON has finished. Since nothing about this incident is templated, the analysis is effectively the whole ticket.
Rationale
Any detection library has an edge. New techniques appear, familiar ones show up in unfamiliar forms, and legitimate software occasionally behaves in ways that resemble an attack. Incidents at that edge cannot be routed by shape, because there is nothing yet to recognise them by.
Sending them for analysis is what keeps that edge covered. The alternative would be dropping them at L1, and that is precisely where genuinely novel activity would be lost. An attacker doing something that has not been seen before produces exactly this kind of incident: unrecognised, uncategorised, and easy to discard on the grounds that nothing matched it.
It is also how the routing improves. An unrecognised pattern that turns out to matter, and that recurs, earns a shape of its own with handling to match.
Follow-up
Follow these steps to adequately handle this ticket:
- If the ticket is empty, wait. The analysis is still running.
- Read the analysis. Because nothing about this incident is templated, the ticket content is the substance. It describes what was observed, what the analysis concluded, and what if anything you should do.
- Provide context if asked. Unrecognised incidents are the category where the analysis is most likely to need something only you know: whether a piece of software is expected in your environment, whether a device has an unusual role, whether a process is part of a business application. A quick answer often resolves the whole ticket.
- Follow the recommendation in the ticket rather than a generic checklist. Since the pattern is not a known one, the appropriate response is whatever the analysis establishes, not a standard set of steps.
- Tell us if the activity is normal for you. Where an unrecognised incident turns out to be routine in your environment, saying so lets it be handled at L1 in future rather than analysed afresh each time.