1
Threat Overview
Microsoft Defender now automatically isolates compromised endpoints to prevent lateral movement, targeting organizations using the Defender for Endpoint solution. This capability is currently in testing. The threat aims to disrupt network defenses.
2
Key Intelligence Points
1. Microsoft is testing a new Defender for Endpoint capability to automatically isolate compromised endpoints. 2. The affected scope is organizations using the Defender for Endpoint solution. 3. The attack chain involves compromising endpoints to move laterally across the network. 4. Detection opportunities include monitoring for unusual network activity and endpoint behavior.
3
MITRE ATT&CK Techniques
T1021.002: Remote Services: Windows Remote Management (WinRM)
4
Mitigation & Detection
Implement the new Defender for Endpoint capability or configure network segmentation to isolate compromised endpoints.