Oh, this was weird. Defender is tagging
streaming.infosec.exchange as a C2 at work. Have you ever seen Defender do this @jerry?streaming.infosec.exchange as a C2 at work. Have you ever seen Defender do this @jerry?https://threatvault.paloaltonetworks.com/
Granted this mostly relates to URL filtering on firewalls... I have no idea where XDR gets it's ideas from.
*edit - the more details link does NOT contain any more details.
Nothing but allows on my instance
@jerry @djchateau Also XDR as I was looking at stuff
Alert Name: Uncommon IP Configuration Listing via ipconfig.exe
Alert id: [REDACTED]
Severity: Low
Source: XDR Analytics BIOC
Category: Discovery
Action: Detected
Description: The 'ipconfig' command was executed on [REDACTED] to list the IP configuration for all devices. Child process command line: ipconfig /all. The command line was seen on 0 hosts in the last 30 days
Host: [REDACTED]
X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*