Bert-JanP / Hunting-Queries-Detection-Rules

KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.
https://kqlquery.com
BSD 3-Clause "New" or "Revised" License
1.14k stars 213 forks source link

Microsoft Defender Issue #43

Closed taremooo closed 3 months ago

taremooo commented 3 months ago

My organizations Microsoft Defender custom detection rules have all disappeared, about half of our blocked IOC's have vanished as well. I'd like to know if this is peculiar to anyone and if there is a solution?

Detection

Bert-JanP commented 3 months ago

Hi, I am not aware of this issue. If you have enabled UAL for MDE you can view what caused this activity. If there is no entry and the UAL activities are enabled I suggest creating a support ticket for MS Support to investigate this particular issue. Both Indicator and custom detection rule deletions/changes (and creations) are logged in UAL.