Hi Team, I would like to get notified through email whenever MAR detects a threat. I have gone through threat events but didn't find any event when MAR detected a threat.
Also checked the event filtering in server settings and ensured that all the Active response events are enabled.
Request you to share if there is any reference KB article to configure the email alerts for MAR.
Thanks in advance.
Dear Satish_Talatam,
MAR basically a threat hunting software, which identifies high risk, susp., and monitored files, commands etc. not exactly threats (i know in threat workspace it says threats, but many times it is false positive, or only the programming of software is very poor etc...) and it traces them, so you can check an event flow.
And on other hand these detections has a current state an it can be evolved because of TIE/GTI/ATD reputation score or other red flags etc.
So you can not find any event and you can not make az automatic response regarding MAR detections (Workspace).
But MAR provides custom Triggers, which generates event id's if an "event" on system match on MAR trigger condition.
So in this case you have an event id in ePO and you can create an automatic response based on this id.
BR,
k
Dear Satish_Talatam,
MAR basically a threat hunting software, which identifies high risk, susp., and monitored files, commands etc. not exactly threats (i know in threat workspace it says threats, but many times it is false positive, or only the programming of software is very poor etc...) and it traces them, so you can check an event flow.
And on other hand these detections has a current state an it can be evolved because of TIE/GTI/ATD reputation score or other red flags etc.
So you can not find any event and you can not make az automatic response regarding MAR detections (Workspace).
But MAR provides custom Triggers, which generates event id's if an "event" on system match on MAR trigger condition.
So in this case you have an event id in ePO and you can create an automatic response based on this id.
BR,
k
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA