logo

ENS 10.7 Rolls Back the Curtain on Ransomware

ID: 0641c89f-ce5a-5685-86c0-0b7521c15453

STIX ID: report--0641c89f-ce5a-5685-86c0-0b7521c15453

Feed Name: McAfee Labs Blog

Date Published: 2020-05-07

Date Updated: 2026-04-28

Author: Martin Ohl

...
...

The blog outlines how to harden endpoints against ransomware—particularly RDP- and fileless-based intrusions—by configuring McAfee ENS 10.7 (Threat Prevention, Firewall, Web Control, Adaptive Threat Protection with Enhanced Remediation) and leveraging MVISION EDR and ePO for continuous compliance, hunting, and rapid response. It recommends restricting RDP via firewall allowlists, using GTI-backed reputation and AMSI-integrated script scanning, enabling Story Graph visualizations for detections, and activating Enhanced Remediation to automatically roll back malicious changes, while monitoring ATT&CK-aligned alerts for privilege escalation and lateral movement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.