Findings
Generator
Configuration
Lucidum Reverse
Architecture
Statistics
← All Findings
Vendor:
Microsoft Defender for Endpoint
FIN-270
Weight:
5
4
3
2
1
Confidence:
High
Medium
Low
Edited:
2026-03-06 09:03
Verified
What It Detects
A device has an inactive sensor (no telemetry flowing to Defender) while simultaneously having active high-severity alerts. This creates a blind spot during an active incident — the security team cannot investigate, contain, or remediate the threat because the endpoint is not reporting data. The combination of an ongoing high-severity event with zero visibility represents an immediate and multiplicative risk: the threat is real, but the defender is blind.
MITRE ATT&CK Techniques
Comma-separated, e.g. T1078, T1190
Checks
read-only
Field
Operator
Value
healthStatus
equals
Inactive
severity
equals
High
status
in
['New', 'InProgress']
Remediation
×
×
×
+ Add item
Why It Matters
×
×
×
+ Add item
Save Changes
Export Lucidum