MS Graph message: Indicators that the system is performing defense evasion have been detected. This alert may be indicative of an APT.
Description
MS Graph message: Indicators that the system is performing defense evasion have been detected. This alert may be indicative of an APT.
Query · wazuh
field ms-graph.category="DefenseEvasion"
Fires when
Wazuh evaluates a chain top-down. Every rule above this one must match on the same event before this rule is tested at all.
-
decoded_as=json AND field integration="ms-graph" -
field ms-graph.relationship="alerts|alerts_v2" -
99503MS Graph message: The alert/incident has not been resolved and is not a false positive. anchor level 6field ms-graph.status="resolved" AND field ms-graph.classification="falsePositive" -
99518MS Graph message: Behaviors and indicators that might be a part of an advanced persistent threat (APT) were detected. This includes observed behaviors typical of attack stages, anomalous registry change, execution of suspicious files, and so forth. anchor level 12field ms-graph.severity="medium" -
99565MS Graph message: Indicators that the system is performing defense evasion have been detected. This alert may be indicative of an APT. refinement level 13 this rulefield ms-graph.category="DefenseEvasion"