logo

Containing a domain compromise: How predictive shielding shut down lateral movement

ID: 895376e0-5c1d-5340-b3fe-e97a44a8029e

STIX ID: report--895376e0-5c1d-5340-b3fe-e97a44a8029e

Feed Name: Microsoft Security

Threat Score
80/100

Date Published: 2026-04-17

Date Updated: 2026-04-28

Author: Microsoft Defender Security Research Team

...
...

A public-sector organization experienced a multi-stage Active Directory compromise after an IIS file-upload vulnerability was exploited to drop web shells; the adversary escalated to SYSTEM (BadPotato), performed large-scale credential dumping (Mimikatz, NTDS snapshots), abused Exchange delegation, and conducted password spraying and lateral movement. Microsoft Defender’s attack disruption—and later the predictive shielding feature—automatically revoked sessions and preemptively contained context-linked, high-privilege accounts, blocking pivots and limiting the adversary’s blast radius until the campaign lost momentum.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.