← All Findings
Vendor: Microsoft Defender for Endpoint FIN-200 Weight: Confidence: Edited: 2026-03-06 09:05

What It Detects

MITRE ATT&CK Techniques

Comma-separated, e.g. T1078, T1190

Checks read-only

FieldOperatorValue
managedBy is_empty True

Remediation

Why It Matters

Export Lucidum