Microsoft Defender XDR’s automatic attack disruption
Before going into attack scenarios, let us look at what automatic attack disruption. Microsoft Defender XDR, as well as other Microsoft security solutions, shares and correlates a huge number of signals daily. Automatic attack disruption was introduced initially in 2022, and the idea behind is to identify ongoing complex and sophisticated attacks with high confidence and execute mitigation actions automatically (containing compromised assets, such as identity and endpoints).
An overview of Microsoft Defender XDR’s automatic attack disruption
Microsoft Defender XDR’s automatic attack disruption mechanism leverages Microsoft AI models and threat research insights to detect possible attacks. One of the main advantages of using automatic attack disruption (compared to other XDR and SIEM solutions) is that the feature is built into the Microsoft Defender XDR platform. It’s automatically enabled when solutions...