Containing a domain compromise: How predictive shielding shut down lateral movement
ID: 895376e0-5c1d-5340-b3fe-e97a44a8029e
STIX ID: report--895376e0-5c1d-5340-b3fe-e97a44a8029e
Feed Name: Microsoft Security
Date Published: 2026-04-17
Date Updated: 2026-04-28
Author: Microsoft Defender Security Research Team
A public-sector organization experienced a multi-stage Active Directory compromise after an IIS file-upload vulnerability was exploited to drop web shells; the adversary escalated to SYSTEM (BadPotato), performed large-scale credential dumping (Mimikatz, NTDS snapshots), abused Exchange delegation, and conducted password spraying and lateral movement. Microsoft Defender’s attack disruption—and later the predictive shielding feature—automatically revoked sessions and preemptively contained context-linked, high-privilege accounts, blocking pivots and limiting the adversary’s blast radius until the campaign lost momentum.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
