Findings
Generator
Configuration
Lucidum Reverse
Architecture
Statistics
← All Findings
Vendor:
Microsoft Defender for Endpoint
FIN-272
Weight:
5
4
3
2
1
Confidence:
High
Medium
Low
Edited:
2026-03-06 09:03
Verified
What It Detects
A device has not reported to Defender for over 30 days and carries a high risk score. The risk score reflects the aggregate threat posture calculated from alerts, vulnerabilities, and misconfigurations. When combined with a stale agent, this means a high-risk device has been drifting without any security oversight — no new detections are firing, no remediation is possible, and the risk score likely underestimates the actual current risk since no new data has been collected.
MITRE ATT&CK Techniques
Comma-separated, e.g. T1078, T1190
Checks
read-only
Field
Operator
Value
lastSeen
older_than_days
30
riskScore
equals
High
Remediation
×
×
×
×
+ Add item
Why It Matters
×
×
×
+ Add item
Save Changes
Export Lucidum