Findings
Generator
Configuration
Lucidum Reverse
Architecture
Statistics
← All Findings
Vendor:
Microsoft Defender for Endpoint
FIN-268
Weight:
5
4
3
2
1
Confidence:
High
Medium
Low
Edited:
2026-03-06 09:03
Verified
What It Detects
A device classified as high-value in Defender is running an end-of-life operating system. High-value devices typically host critical business applications, sensitive data, or key infrastructure services. Running an unsupported OS on these assets creates disproportionate organizational risk because compromise of a high-value target has amplified blast radius.
MITRE ATT&CK Techniques
Comma-separated, e.g. T1078, T1190
Checks
read-only
Field
Operator
Value
osPlatform
in
['Windows7', 'Windows8', 'Windows10', 'WindowsServer2008R2', 'WindowsServer2012R2', 'WindowsServer2016']
deviceValue
equals
High
Remediation
×
×
×
×
+ Add item
Why It Matters
×
×
×
×
+ Add item
Save Changes
Export Lucidum