Bug in the Microsoft 365 Defender format update
Incident Report for SEKOIA.IO
Resolved
Today at 11:16 CEST, an issue with an unexpected surge in alerts arose, which has since been resolved. This was linked to a recent update in the Microsoft 365 Defender format, which included relocating certain process information to process.parent for AdvancedHunting-DeviceEvents and AdvancedHunting-DeviceProcessEvents.

Resolution Summary:

- The Microsoft Defender for Endpoint integration was reverted to its previous version to stop potentially false positive alerts.
- We are addressing and dismissing non-relevant alerts that were raised.

Thank you for your understanding and patience. The incident is now fully resolved.
Posted Oct 09, 2024 - 11:30 CEST