Microsoft Defender XDR Blind Spot Can Hide Public Connections Behind FourToSixMapping

Security teams relying on Microsoft Defender XDR’s DeviceNetworkEvents table for hunting and detection may be missing critical external network connections due to a lesser-known IP address classification quirk. The issue centers on FourToSixMapping, a RemoteIPType value that can cause public IP traffic to slip past detection logic that filters strictly on RemoteIPType == “Public”. According […]

The post Microsoft Defender XDR Blind Spot Can Hide Public Connections Behind FourToSixMapping appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: