logo

How Microsoft Defender protects high-value assets in real-world attack scenarios

ID: 40e81a58-768a-539f-95c7-4ce4a68042a4

STIX ID: report--40e81a58-768a-539f-95c7-4ce4a68042a4

Feed Name: Microsoft Security

Threat Score
70/100

Date Published: 2026-03-27

Date Updated: 2026-04-28

Author: Microsoft Defender Security Research Team

...
...

This Microsoft Defender article explains threats to High-Value Assets (HVAs) — domain controllers, web/Exchange servers, and identity infrastructure — describing observed attacker techniques (NTLM relay, reverse SSH tunnels, remote scheduled tasks, ntdsutil exfiltration attempts, and webshells) and how asset-aware detection and automated disruption via Microsoft Security Exposure Management and Defender can detect, block, and remediate these high-impact attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.