mamot.fr is one of the many independent Mastodon servers you can use to participate in the fediverse.
Mamot.fr est un serveur Mastodon francophone, géré par La Quadrature du Net.

Server stats:

3.2K
active users

#microsoftdefender

0 posts0 participants0 posts today

Microsoft Defender Enhances Cybersecurity with Automated IP Containment for Undiscovered Endpoints

In a bold move to fortify network security, Microsoft is rolling out a new feature in Defender for Endpoint that isolates undiscovered devices, effectively blocking potential lateral movement by cyber...

news.lavx.hu/article/microsoft

Frage in die Runde:
Hat jemand von euch (oder kennt jemanden) in den letzten Jahren eine Endpoint Protection oder ein EDR in der Firma eingeführt (z.B. Jamf Protect, Microsoft Defender for Business o.ä.)?

Wie lange hat das ca. gedauert (inkl. datenschutzrechtlichen und IT-Sicherheitsabklärungen)?

Wäre um ein paar Erfahrungswerte aus der Schweiz und dem EU-Raum dankbar 🙏

I noticed today that a lot of people are struggling with antivirus alerts, specifically Microsoft Defender:

1) try to understand the alarm itself and at which point in the attack this would happen: phishing email = early, credential access (especially admin credentials) or suspicious C2 IPs = middle, ransomware/data upload = late.

2) what should be the attackers previous and next step then? (just look at 1 again: early/middle/late)

3) can you see this previous/next step in the logs? Look especially for evidence of execution. Attackers want to "do" something. Executables, scripts, PowerShell, command line, services, scheduled tasks?

If you cannot see any previous or any next steps, ask yourself if you're blind (are your logs empty? Timeframe not available?) or if there really aren't any. If there aren't any, it's likely a false positive. If there are, escalate.

Happy hunting!

I select 103 emails to submit to Microsoft for review, they are all falsely classified as phishing and spam.

The submit check box is greyed out, a tooltip says to direct select 100 or less emails to submit.
I deselect 3 emails and try again, the check box is still greyed out, but now there's no tooltip. Broken trash costs a fortune.
#microsoft #microsoft365 #microsoftdefender