Forum Discussion

DS99's avatar
DS99
Copper Contributor
Mar 07, 2025

Alerts doesn't works? - EDR source

Hi,

I'm new to Defender and I want to understand a couple of things.

I deployed Defender P2 on a windows host and I tried to attack it with rdp brute force.

The Timeline show me that the technique used is T1110:BruteForce but I don't see any alert in the console.

Is normal? There is a way to tell to defender that it must create an alert when it see a brute force attack?

Even worse with a couple of tests on a linux host.

I'm sure that the EDR is engaged because I tested the alert with the default scripts.

Even with the execution of a rootkit..

Thanks

 

Resources