logo

How Microsoft Incident Response and Microsoft Defender for Identity work together to detect and respond to cyberthreats

ID: 01a86b6b-f0c8-5eef-8901-6021f0588fee

STIX ID: report--01a86b6b-f0c8-5eef-8901-6021f0588fee

Feed Name: Microsoft Security

Threat Score
70/100

Date Published: 2024-03-21

Date Updated: 2026-04-28

Author: Microsoft Incident Response

...
...

This Microsoft security blog describes a human-operated ransomware intrusion that began when a user clicked a malicious link, leading to Qakbot infection, credential harvesting, lateral movement, and imminent ransomware activity; Microsoft Incident Response used Defender for Identity and Defender for Endpoint to identify affected accounts, contain and evict the actor, and recommends layered defenses—MFA, conditional access, endpoint protections, honeytokens, and Copilot for Security—to strengthen identity posture and resilience.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.