Microsoft Defender XDR Blind Spot Can Hide Public Connections Behind FourToSixMapping
ID: bca1b885-9fd3-5dfe-8c01-3458142b4474
STIX ID: report--bca1b885-9fd3-5dfe-8c01-3458142b4474
Feed Name: cybersecurityNews.com
Detect FYI identified a Defender XDR logging/detection blind spot where IPv4-mapped IPv6 addresses (e.g., ::ffff:8.8.8.8) are classified as RemoteIPType == "FourToSixMapping" rather than "Public", causing detection queries that filter only on RemoteIPType == "Public" to miss real external connections (including covert C2). The report explains the technical cause, demonstrates KQL pitfalls, and recommends normalizing the address (strip the ::ffff: prefix) and treating both Public and FourToSixMapping as external when building detections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
