MS Graph message: Indicators that the system is performing defense evasion have been detected. This alert usually originates from common malware and threats, rather than APT activity. Check the system for signs of infection.
Description
MS Graph message: Indicators that the system is performing defense evasion have been detected. This alert usually originates from common malware and threats, rather than APT activity. Check the system for signs of infection.
Query · wazuh
field ms-graph.category="DefenseEvasion"
Fires when
Wazuh evaluates a chain top-down. Every rule above this one must match on the same event before this rule is tested at all.
-
decoded_as=json AND field integration="ms-graph" -
field ms-graph.relationship="alerts|alerts_v2" -
99503MS Graph message: The alert/incident has not been resolved and is not a false positive. anchor level 6field ms-graph.status="resolved" AND field ms-graph.classification="falsePositive" -
field ms-graph.severity="unknown" -
99546MS Graph message: Indicators that the system is performing defense evasion have been detected. This alert usually originates from common malware and threats, rather than APT activity. Check the system for signs of infection. refinement level 12 this rulefield ms-graph.category="DefenseEvasion"
Rule dependencies
Depends on
-
composes · Wazuh if_sid
99512 -
composes · Wazuh if_sid
99517