Microsoft Defender Gains Auto-Isolation Feature to Block Ransomware Spread
ID: 52938a32-b42e-5fd3-a130-cd3bbc5b1206
STIX ID: report--52938a32-b42e-5fd3-a130-cd3bbc5b1206
Feed Name: GBHackers
Microsoft Defender XDR introduces an automatic attack disruption feature that autonomously contains ransomware and advanced attacks by correlating signals across endpoints, identities, email, and SaaS to form high-confidence incidents and executing automated containment actions (device isolation, IP containment, port filtering on critical assets, and account suspension). The capability uses ensemble machine learning and validated detectors, provides administrative controls and exclusions, integrates with existing Defender workflows, and emphasizes reversible actions and monitoring rather than reporting any specific incident or compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
