Hi All,
I have observed lots of demo computers have been randomly added to pre-default group of Secure endpoint console i.e (protect, audit, triage). However i have deleted all those random computers and group also. What it could be? Can it be a some attack in my network? .
PLease find attached snap of Audit logs
