Defender's Remote Connections Blind Spot: FourToSixMapping
ID: 3c506b56-1091-513d-8691-210e65995b97
STIX ID: report--3c506b56-1091-513d-8691-210e65995b97
Feed Name: Detect FYI
This blog post explains how overly constrained KQL queries in Microsoft Defender XDR can generate false negatives by filtering on RemoteIPType == "Public" or relying on ipv4_is_private(), which returns null for IPv4-mapped IPv6 addresses (FourToSixMapping). The author demonstrates the issue with examples and provides KQL fixes and normalization (removing the "::ffff:" prefix) to ensure external communications logged as FourToSixMapping are detected.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
