How Microsoft Defender protects high-value assets in real-world attack scenarios
ID: 40e81a58-768a-539f-95c7-4ce4a68042a4
STIX ID: report--40e81a58-768a-539f-95c7-4ce4a68042a4
Feed Name: Microsoft Security
Date Published: 2026-03-27
Date Updated: 2026-04-28
Author: Microsoft Defender Security Research Team
This Microsoft Defender article explains threats to High-Value Assets (HVAs) — domain controllers, web/Exchange servers, and identity infrastructure — describing observed attacker techniques (NTLM relay, reverse SSH tunnels, remote scheduled tasks, ntdsutil exfiltration attempts, and webshells) and how asset-aware detection and automated disruption via Microsoft Security Exposure Management and Defender can detect, block, and remediate these high-impact attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
