詳細検索

Have you seen all the security alerts? Microsoft Defender's Noise Reduction

Avatar
by 西田
3 min read

Have you seen all the security alerts? Microsoft Defender's Noise Reduction
Translated from 日本語 • View original
西田
西田

Hello! Hello! This is Nishida from Colorkrew Security. Have you implemented Microsoft Defender but are you having these problems?

 

  • "Defender alerts, too many to respond to..."
  • "I don't know which one is really dangerous"
  • "There were too many notifications, and no one ended up seeing anyone."

This is typical of "alert fatigue" that occurs in many companies.

Therefore, this time, we will tell you the operational points for the Microsoft Defender product group to narrow down alerts to what you really need to see.

1. Microsoft Defender is excellent but "talks too much"

The Microsoft Defender suite of products, such as for Endpoint, Office 365, Identity, and Cloud Apps, is highly capable. However, on the other hand, the downside is that there are many alerts anyway.

In particular, the following phenomena are common:

  • Notify as a "warning" even for regular scans and automated processes
  • Alerts every time even minor activities on the same device and user
  • Mixed with false positives and minor detections with no business impact

2. Common "Alert Operation Failures"

  • Case: Notifying Teams of all alerts
    Problem: Too much noise to bury really important alerts
  • Cases: All severity "low" is also targeted.
    Problem: High burden on the person in charge and time-consuming analysis
  • Case: Checking only on the Defender portal
    Problem: Team collaboration and record-keeping are not possible, and knowledge is not accumulated

3. 3 Points to Reduce Noise

(1) Clarify "thresholds" by severity

  • "Medium" or higher will be prioritized, and "low" will be ignored in principle or subject to monthly review.
  • Users with business impact (executives, developers) are determined by different rules according to the environment.

(2) Exclude Automatically Remediated Alerts from Notifications

  • Defender for Endpoint has many automated events, so focus notifications only on those that require manual action.

(3) Response rules for "repeated alerts"

  • For alerts that appear every time on the same app or device, consider suppressing/excluding settings
  • Examples: "False positives for legitimate internal tools" and "Scanning from a validation environment"

4. Colorkrew Security helps you optimize Defender alerts

To decide what to leave and what to ignore, you need to understand both the system and the business.

Colorkrew Security can help you with:

  • Assist in alert design and tuning of Microsoft Defender products
  • Formulation of operational rules according to severity and impact
  • Integration into Microsoft Sentinel and SIEM and case management
  • Creating an environment where "only the alerts you need to see will be received"

"Pick up only one case from the pile of alerts that needs to be addressed" - we will create a system for this.

5. Summary: Alerts from "See All" to "Only See What's Meaningful"

  1. Point: Defender is excellent, but has a lot of alerts
    What: If you don't reduce noise, you may miss the alerts that need to be addressed.
  2. Key points: Tuning and operational design are the keys to success
    Contents: Response rules, notification settings, and severity management are required
  3. Point: Colorkrew helps you optimize alerts
    Contents: Provides rule design, notification design, and monitoring in line with actual operation

"Don't you stop seeing all the alerts?"

Colorkrew Security provides alert operation optimization support services centered on Microsoft Defender.
From initial design to improvement proposals, please leave it to us!

Related Articles