Endpoint Detection and ResponseEndpoint Protection with Endpoint Detection and ResponseAdvanced Threat Protection Platform
Issue/Introduction
Post-upgrade, our teams see a number of EDR alerts, some dating back months, associated with old Trojan/C2 activity.
Environment
Release : 4.6.0
Component :Upgrade, TAA, and Incident creation
Cause
After upgrade to EDR 4.6, EDR automatically enrolls for TAA with all of the SEPM licenses it can associate with the customer.
EDR then receives any existing events that are already present in TAA.
If those events would have generated an event if they had been received previously, EDR will generate an event when it receives those events after upgrade and auto-enroll.
Resolution
To confirm the issue with UI logs
On incidents, click on the Incident number of an incident
If the Related Events have a timestamp from before the software upgrade, click the greater than symbol at the left of the row to expand the entry.
In the details of the Related Event, find the log_time (when EDR received the events)
If the event has a log_time after the software upgrade, this Incident may have been generated as a late hit from events received from TAA Auto-enroll.
On Logging, click the System Activity tab
Scroll through the System Activity events looking for the Stop All Services event from when admin team restarted EDR after the update
To search for the auto-enroll event, scroll up from the Stop All Services event
If you have Incidents where the Related events have log_time from after the TAA auto-enroll and other timestamps from before the EDR 4.6 update, you have this issue.