Security teams relying on Microsoft Defender XDR’s DeviceNetworkEvents table for hunting and detection may be missing critical external network connections due to a lesser-known IP address classification quirk. The issue centers on FourToSixMapping, a RemoteIPType value that can cause public IP traffic to slip past detection logic that filters strictly on RemoteIPType == “Public”. According […]
The post Microsoft Defender XDR Blind Spot Can Hide Public Connections Behind FourToSixMapping appeared first on Cyber Security News.
Read the original article: