Microsoft Defender For Endpoint Service Failed To Connect To The Server

Rule Info

Name
Microsoft Defender For Endpoint Service Failed To Connect To The Server
Author
Nasreddine Bencherchali (Nextron Systems)
Description
Detects instances where the Microsoft Defender for Endpoint service has failed to connect to the server. This could be due to issues with the internet connectivity or a potential attackers blocking traffic towards defender domains.
Date
2024-07-09 00:00:00
Modified
None
Id
6d653793-f185-404a-be5a-56a8d195f236
Tags
attack.defense-evasion attack.t1562.001
Type
Nextron Sigma feed only (private)

Rule History