Microsoft Says Defender Can Stop Ransomware In 128 Seconds—Here’s How | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


With the business media and many so-called cybersecurity thought leaders focusing on AI-powered breaches these days, you might be forgiven for thinking the ransomware threat is a thing of the past. You would be very wrong indeed, however, as newly published reports have confirmed. Reported ransomware incidents have risen year-on-year, with attackers increasingly using AI to automate and scale, IBM said. Meanwhile, BlackFog has confirmed that attacks targeting the service sector have increased by 221% from Q1 to Q2 this year. Anything that can give your organization the edge in fighting off the threat, therefore, is worth investigating. And Microsoft has just published a claim that a new response action within Defender can extend “autonomous protection directly to compromised endpoints” and halt a ransomware attack chain before a second-stage payload establishes persistence or moves beyond the host, in 128 seconds from “the first high-severity alert to completed isolation.”

ForbesMicrosoft Has Paid A Record $20 Million For Security Vulnerabilities

How Microsoft Killed A QNET Ransomware Attack In A Little Over Two Minutes From Start To Finish

QNET is a global multi-level marketing and direct-selling company with a distributed workforce, and so a fairly typical target of ransomware actors. A distributed workforce is a magnet for threat actors looking for an in, and a global business signifies worthwhile ransom demands to be made if an attack is successful. The case study detailed by Microsoft has revealed that on this occasion the attackers employed a legitimate Windows tool on a compromised endpoint to fetch the malicious remote ransomware payload. The use of such a living-off-the-land technique can be very profitable as it often slips past defenses.

Often ransomware attacks involve identity through shared or otherwise compromised credentials, and as James Maude, the field CTO at BeyondTrust, told me, “too many environments still have administrator accounts with permanent, always-on access to both IT and OT domains,” which is just asking for lateral movement exploitation. The Microsoft report detailed, however, that incidents such as this one often start with initial access directly on the device, which gives the threat actor a chance to establish an endpoint foothold from where multiple persistence mechanisms can be dropped. “This means that acting against the user’s identity alone is no longer enough to dismantle the threat,” Microsoft said, because that actor can “establish persistence, steal credentials, inject into processes, and prepare follow-on stages directly from the compromised endpoint itself,” without the need for immediate lateral movement.

Which is where device isolation comes into play. As the name would imply, this closes the threat gap by isolating the compromised device. And isolating it within seconds, 128 in this particular case.

“When Microsoft Defender determines with high confidence that an endpoint is compromised,” the report said, confirming that AI-driven correlation and real-time analysis are employed to reach a 99% confidence verdict, “it isolates the device to immediately stop attacker activity and reduce the risk of further impact.” And isolation means just that: external network connectivity is blocked, although access to security services is maintained and the organization itself can enable “customer-defined services or exclusions to continue functioning.” The important takeaway here is that such device isolation, or ransomware containment action if you prefer, breaks the lateral movement opportunity and gives the security team time to breathe.

In the case of the QNET attack, that meant the difference between “a contained initial living-off-the-land binary execution and a fully detonated second-stage payload that had achieved credential theft and persistence,” according to Microsoft.

“The device isolation was triggered almost immediately,” A QNET spokesperson said, “which gave us confidence that the threat was contained early before it had any chance to spread.”

Of course, what this doesn’t mean is that you can ignore the basics of ransomware prevention and mitigation. Device isolation alone, if you’ll excuse the pun, is not a magic Microsoft bullet. “Regardless of the ransomware actor, the foundational controls still matter,” Trey Ford, chief strategy and trust officer at Bugcrowd reminds us. “Knowing your total attack surface, testing your environment with an eye toward efficient remediation is key.” And that means employing enterprise controls, including privileged account management, careful inventory of service accounts, and multi-factor authentication for domain admin and remote access.

——————————————————–


Click Here For The Original Source.

.........................

National Cyber Security

FREE
VIEW