Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

v20.events.data.microsoft.com #180

Closed
beerisgood opened this issue Oct 25, 2019 · 8 comments
Closed

v20.events.data.microsoft.com #180

beerisgood opened this issue Oct 25, 2019 · 8 comments

Comments

@beerisgood
Copy link

Related to #138

This domain is needed for machine proxy and Internet connectivity settings and Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)
https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/configure-proxy-internet

@crazy-max
Copy link
Owner

Hi @beerisgood, I have to take a closer look on this one as it involves other "events" rules. Keep you in touch.

@ghost
Copy link

ghost commented Nov 25, 2019

Instead of removing the IP put the option to the extra extra list.
Seriously, all this data harms the freaking environment at this stage.

@savchenko
Copy link

Debatable. While it might be beneficial in certain places where client machines are relying on ATP (requires Enterprise Windows license with active subscription by the way), in others users might not be pleased by the fact their OS leaks information about work environment to Microsoft.

@beerisgood
Copy link
Author

Leak information? Don't think so. Or did you have any facts about that?

Microsoft include more and more security stuff from higher editions to lower and also this connection was established from my Pro edition.
We shouldn't block serious windows features which reduce security. Only blocking telemetry is the goal of this project isn't it?

I would agree with @airbee7337 to put this domain on extra list. Then anyone with that need can block it

@savchenko
Copy link

connection was established from my Pro edition

...which implies that it's being used not only for ATP, right? As the latter can't be run on "Pro" edition.

@beerisgood
Copy link
Author

As i write already. Microsoft add ATP features to lower editions already, like ASR (Attack surface reduction) which is listed on ATP features site: https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/overview

So this connection is fine, as ASR for example get new definitions/ rules from that

@savchenko
Copy link

Sorry, I think we were talking about different features. I was referring specifically to what Microsoft offers under an umbrella of "cloud-delivered protection".

crazy-max added a commit that referenced this issue May 8, 2020
Update IPs for extra, spy and update rules
Move Microsoft Defender ATP endpoints to extras rules (#180)
@crazy-max
Copy link
Owner

@beerisgood Has been moved to the extra rules.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants