False Positives Microsoft Teams Large Upload

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

False Positives Microsoft Teams Large Upload

L3 Networker

Hey,


I need your help.

We are receiving alerts "XDR Incident 945 - 'Large upload (generic)' generated by #XDR Analytics detected...

 

Basically, this appears when the user makes a call, shares documents, or shares their screen (using Microsoft Teams).

 

In the #XSOAR event I can see that the processname is ms-teams.exe and the destination ip is from Microsoft Azure networks

 

I know this is related to screen sharing because it has happened to my user/laptop.

I tried to create a pre-process rule to do autoclose....in the test... pre-process it works, in practice it doesn't.
Does this situation happen to everyone?
any suggestion??

Best regards
Tiago Marques
2 REPLIES 2

L4 Transporter

Hi @tlmarques ,

 

Normally, preprocessing script should discard those incidents if configured properly. I need to see your script and the raw data coming from the incident to be able to help. If you are still facing the issue, please try to provide relevant part from incident data with demisto.incident() and your preprocessing script.

L3 Networker

Hi

I've found the problem... missing parameter on incoming mapper.

 

Best regards
Tiago Marques
  • 768 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!