Site icon TheCyberThrone

Microsoft Automatic Attack Disruption in Defender 365

Advertisements

Earlier this week, Microsoft announced that it’s automatic attack disruption capabilities in Microsoft 365 Defender. Its enterprise defense suite will now help organizations disrupt business email compromise and human-operated ransomware attacks.

The signals on which Microsoft 365 Defender takes automated disruption actions are gathered from endpoints, identities, email, collaboration, and SaaS apps. They are then aggregated and automatically analyzed, and if a high level of confidence is established so they acted upon it.

Advertisements

Automatic attack disruption operates in 3 key stages:

  1. Detect malicious activity and establish high confidence
  2. Classification of scenarios and identification of assets controlled by the attacker
  3. Trigger automatic response actions using the Microsoft 365 Defender protection stack to contain the active attack

The current public preview, the automatic attack disruption capabilities include:

Security teams can customize the configuration for automatic attack disruption. Also, to ensure that automatic actions don’t negatively impact the health of a network, Microsoft 365 Defender automatically tracks and refrains from containing network-critical assets and built client-side fail safe mechanisms into the containment lifecycle.

According to a research report , the average time to complete a ransomware attack dropped from 60 days down to less than 4 days and the rate at which attackers target employees via compromised email accounts and by exploiting existing email threads has doubled.

Exit mobile version