Microsoft Defender will soon be a lot better at stopping corporate cyberattacks


A number of advanced Microsoft 365 Defender features first announced last year as a means of stopping ransomware and business email compromise (BEC) attacks, have now reached public preview, the company has announced.
The features, called “automatic disruption” use “high-confidence Extended Detection and Response (XDR) signals across endpoints, identities, email, and SaaS apps”, Microsoft explained, saying they’ll help contain active security attacks “quickly and effectively”.
They’ll work by automatically disabling, or restricting, devices and user accounts that the threat actors have compromised and are actively using in an attack.
Limited impact
By shutting off this access, Microsoft hopes the attackers won’t be nearly as effective as they should be, and at the same time, SOC teams get more time to deploy additional countermeasures.
As a result, ransomware and BEC attacks should have a more limited impact on the target organization, the company claims.
Automatic attack disruption operates in three stages. In the first stage, the attack is detected, and “high confidence” is established. In the second stage, different scenarios are classified, as well as assets that the attackers are currently controlling. Finally, in the third stage, automatic response actions are triggered via Microsoft 365 Defender, containing the attack and minimizing its impact.
As the name suggests, the activity of these new features is automatic, which might not sit well with some cybersecurity professionals. Microsoft seems to be aware of this fact, stating that the number of signals used should ease anyone’s anxiety around automation:
“We understand that taking automatic action can come with hesitation, given the potential impact it can have on an organization,” the company said. “That’s why automatic attack disruption in Microsoft 365 Defender is designed to rely on high-fidelity XDR signals, coupled with insights from the continuous investigation of thousands of incidents by Microsoft’s research teams.”
Ransomware continues to be one of the most disruptive forms of cybercrime out there. Businesses are advised to train their employees on the dangers of phishing and to make sure they set up a robust backup solution. An antivirus, a firewall (opens in new tab), and multi-factor authentication are also considered best practices.
Audio player loading… A number of advanced Microsoft 365 Defender features first announced last year as a means of stopping ransomware and business email compromise (BEC) attacks, have now reached public preview, the company has announced. The features, called “automatic disruption” use “high-confidence Extended Detection and Response (XDR) signals across…
Recent Posts
- Meta’s AI chatbot will soon have a standalone app
- Framework’s Laptop 12 Could Inject New Life Into Budget Portable PCs
- CRKD teamed up with Gibson to make new guitar controllers
- Amazon CEO says ‘beautiful’ new Alexa hardware is coming this fall
- Cricut’s new crafting machines are more accurate, faster, and cheaper
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010