URL has been copied successfully!
Microsoft Defender XDR Blind Spot Lets Public C2 Traffic Evade Detection Queries
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

Microsoft Defender XDR Blind Spot Lets Public C2 Traffic Evade Detection Queries

Microsoft Defender XDR users may inadvertently overlook command-and-control (C2) traffic when searching for Internet-bound connections due to a specific behavior in how IP addresses are classified. This issue arises from Kusto Query Language (KQL) detections that depend solely on filtering by RemoteIPType == >>Public<< in the DeviceNetworkEvents table. As a result, traffic destined for public […] The post Microsoft Defender XDR Blind Spot Lets Public C2 Traffic Evade Detection Queries appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

First seen on gbhackers.com

Jump to article: gbhackers.com/microsoft-defender-xdr-blind-spot/

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link