MicrosoftLearning / SC-200T00A-Microsoft-Security-Operations-Analyst

MIT License
277 stars 211 forks source link

Module 2 Lab 1 Ex2 Task 5 - Simulation Tutorial #211

Closed arnoldvilleneuve closed 11 months ago

arnoldvilleneuve commented 12 months ago

Contact Details

arnold.villeneuve@rogers.com

What happened?

Learning Path 2 - Lab 1 - Exercise 2 - Mitigate Attacks with Microsoft Defender for Endpoint

Description of issue: Task 2 Step 5.

Step 5. Repeat the last 3 steps to run another tutorial, Automated investigation (fileless attack).

Notepad does not open as described in the tutorial. Script fails to run and is blocked by virus scanner. A log entry is created stating the script was blocked by virus scanner.

This failure happened for all students.

Module 2 Lab 1 Exercise 2 Task 2 Step 5

Lab

Lab 02 Exercise 02 Mitigate Attacks with Microsoft Defender for Endpoint

Relevant screenshots

paste here 😉 Module 2 Lab 1 Exercise 2 Task 2 Step 5

Do you want to help us? 👏

KenMAG commented 12 months ago

I'll check this today.

KenMAG commented 12 months ago

I was able to reproduce this. And this is new. I'll investigate what changed. Thanks for reporting.

KenMAG commented 11 months ago

For now, I am remarking this out of the instructions.