How Microsoft Incident Response and Microsoft Defender for Identity work together to detect and respond to cyberthreats
ID: 01a86b6b-f0c8-5eef-8901-6021f0588fee
STIX ID: report--01a86b6b-f0c8-5eef-8901-6021f0588fee
Feed Name: Microsoft Security
This Microsoft security blog describes a human-operated ransomware intrusion that began when a user clicked a malicious link, leading to Qakbot infection, credential harvesting, lateral movement, and imminent ransomware activity; Microsoft Incident Response used Defender for Identity and Defender for Endpoint to identify affected accounts, contain and evict the actor, and recommends layered defenses—MFA, conditional access, endpoint protections, honeytokens, and Copilot for Security—to strengthen identity posture and resilience.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
