Microsoft Defender for Cloud
Cloud and workloads

Validate alerts in Microsoft Defender for Cloud

In brief

The article now uses clearer alert descriptions, identifies sample alerts in delivery guidance, separates Defender for Endpoint prerequisites, and refines Windows and Defender for Containers testing instructions.

What Defender admins need to know

Administrators validating alerts can follow the clearer prerequisites and testing steps, including checks for the Defender for Endpoint agent and Real-Time protection.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

What are security alerts?

Alerts are notifications that Defender for Cloud generates when it detects threats on your resources. It prioritizesDefender for Cloud ranks alerts by severity and lists the alerts alongthem with thekey details. You can use this information needed to quickly investigate theeach problem. Defender for Cloud also provides recommendationssteps to help you remediate an attack.

For more information, see Security alerts in Defender for Cloud and Managing and responding to security alerts.

Generate sample security alerts

If you're using use the new preview alerts experience as described in Manage and respond to security alerts in Microsoft Defender for Cloud,experience, you can create sample alerts from the security alerts page in the Azure portal. For more details, see Manage and respond to security alerts in Microsoft Defender for Cloud.

Create sample alerts

:::image type="content" source="media/alert-validation/notification-sample-alerts-creation.png" alt-text="Screenshot showing notification that the sample alerts are being generated." lightbox="media/alert-validation/notification-sample-alerts-creation.png":::

After a few minutes, the sample alerts appear on the security alerts page. TheyThe sample alerts also appear anywhere else that you've configured to receive your Microsoft Defender for Cloud security alerts (connected SIEMs, email notifications, and so on).

:::image type="content" source="media/alert-validation/sample-alerts.png" alt-text="Screenshot showing sample alerts in the security alerts list." lightbox="media/alert-validation/sample-alerts.png":::

Simulate alerts on your Azure virtual machines (VMs) (Windows)

Before you begin, make sure that Microsoft Defender for Endpoint runs with Real-Time protection enabled. To verify this setting, see Configure real-time protection in Microsoft Defender Antivirus.that:

After the Microsoft

On the machine where you want to simulate the attacked resource.

Opentest, open an elevated command-linecommand prompt on the device and run the script:

  1. Go to Start and type cmd.

  2. Right-select Command Prompt and select Run as administrator.

    :::image type="content" source="media/alert-validation/powershell-no-exit.png" alt-text="Screenshot showing PowerShell message line." lightbox="media/alert-validation/powershell-no-exit.png":::

Alternatively, you can use the EICAR test string to perform this test.simulate the alert on Windows. Create a text file, paste the EICAR line, and save the file as an executable file to your machine's local drive.

Simulate alerts on your Azure virtual machines (VMs) (Linux)

Before you begin, make sure that Microsoft Defender for Endpoint runs with Real-Time protection enabled. To verify this setting, see Configure real-time protection in Microsoft Defender Antivirus.that:

After the

  • The Microsoft Defender for Endpoint agent is installed on your machine as part of Defender for Servers integration, follow these steps fromintegration.
  • Microsoft Defender for Endpoint runs with Real-Time protection enabled. To verify this setting, see Configure real-time protection in Microsoft Defender Antivirus.

On the machine where you want to besimulate the attacked resource of the alert:resource, follow these steps:

  1. Open a Terminal window, copy and run the following command: curl -O https://secure.eicar.org/eicar.com.txt
  2. The Command PromptTerminal window closes automatically. If successful, a new alert should appear in the Defender for Cloud Alerts blade inwithin 10 minutes.

Simulate alerts on Kubernetes

Defender for Containers provides securitycreates alerts for your clusters and underlying cluster nodes. Defender for Containers monitorsIt watches both the control plane (API server) and the containerizedcontainer workload.

You canTo simulate alerts for the Defender for Containers control plane and the workload usingcontainerized workload, use the Kubernetes alerts simulation tool.

Learn more about defending your Kubernetes nodes and clusters withTo learn more, see Microsoft Defender for Containers.

Simulate alerts for App Service

1. Copy the website name into the URL: `https://<website-name>.azurewebsites.net/This_Will_Generate_ASC_Alert`.
  1. An alert is generated within about 2 to 4 hours.

Simulate alerts for Storage ATP (AdvancedAdvanced Threat Protection)Protection (ATP)

To validate threat detection for Microsoft Defender for Storage, complete the following steps:

  1. Open the Tor browser download page and install the Tor browser.
  2. In the Tor browser, navigate to the SAS URL. You should now see and can download the file that was uploaded.

Test AppServicesSimulate alerts for App Service (EICAR)

To simulate an app services EICAR alert:

Validate Azure Key Vault Threat Detection

To validate Azure Key Vault threat detection, complete the prerequisitescreate a key vault by using the Azure portal and then follow these steps:

Prerequisites

Validation steps

  1. In the TOR Browser, sign out from the Azure portal and close the browser.
  2. After some time, Defender for Key Vault triggers an alert with detailed information about this suspicious activity.

Next stepsRelated content

This article introduced you to theLearn more about alerts validation process. Now that you're familiar with this validation, explore the following articles:and threat detection in Defender for Cloud: