A detection blind spot in Microsoft Defender XDR and related Sentinel hunting logic can cause external command-and-control traffic to be missed when queries filter DeviceNetworkEvents on RemoteIPType == "Public". During a purple-team exercise, an expected alert failed to fire because some outbound connections to external IPv4 destinations were recorded instead as FourToSixMapping, a label used for IPv4-mapped IPv6 addresses such as ::ffff:8.8.8.8. The behavior is consistent with IPv6 addressing rules and can appear when Windows applications use dual-stack sockets.
The issue also affects KQL detections that rely on ipv4_is_private(RemoteIP), because the function can return null for FourToSixMapping values and exclude malicious external traffic from results. Researchers advised defenders to review Microsoft Defender XDR DeviceNetworkEvents queries and normalize mapped addresses by removing the ::ffff: prefix before applying private-versus-public IP logic, reducing false negatives in network hunting and alerting.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
The analysis further found that KQL's ipv4_is_private() returns null for FourToSixMapping values such as ::ffff:8.8.8.8, creating an additional blind spot in Defender XDR and Sentinel queries. The recommended mitigation was to normalize RemoteIP values by stripping the ::ffff: prefix before applying private/public IP logic.
During a purple team exercise, an expected alert for covert external command-and-control traffic failed to trigger because Microsoft Defender XDR logged some external IPv4 destinations as RemoteIPType "FourToSixMapping" instead of "Public". This revealed that hunting and detection queries filtering only on RemoteIPType == "Public" could miss external connections.
RFC 4291 documented the IPv6 addressing architecture, including IPv4-mapped IPv6 addresses of the form ::ffff:w.x.y.z that underpin the FourToSixMapping behavior discussed later.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcemalware.news
Open sourcedetect.fyi
Open sourcelearn.microsoft.com
Open sourcerfc-editor.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.