Microsoft Defender XDR users may inadvertently overlook command-and-control (C2) traffic when searching for Internet-bound connections due to a specific behavior in how IP addresses are classified. This issue arises from Kusto Query Language (KQL) detections that depend solely on filtering by RemoteIPType == >>Public<< in the DeviceNetworkEvents table. As a result, traffic destined for public […] The post Microsoft Defender XDR Blind Spot Lets Public C2 Traffic Evade Detection Queries appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
First seen on gbhackers.com
Jump to article: gbhackers.com/microsoft-defender-xdr-blind-spot/
![]()

