openaev
openaev copied to clipboard
Microsoft Sentinel - Improve our matching to accurately identify Blocked/Prevented
Description
Microsoft Defender alerts are collected in Microsoft Sentinel, but some of the information is not transmitted correctly.
We need to improve our keyword extraction in Sentinel so that if the expectation is 'Prevented' by Microsoft Defender then it should consistent and also be 'Prevented' by Microsoft Sentinel.