Event banner

Microsoft Detection and Response Team (DART) AMA

Event Ended
Tuesday, Mar 15, 2022, 09:00 AM PDT
In-Person

Event details

We are very excited to announce our Microsoft Detection and Response Team (DART) AMA!

 

About DART:
Our job is to respond to compromises and help our customers become cyber-resilient. This is also our team mission. One we take very seriously. And it’s why we are passionate about what we do for our customers. Curious about stories from the front lines of incident response, customer engagements, or the tools we use? Ask us anything.

 

An AMA is a live text-based online event similar to a “YamJam” on Yammer or an “Ask Me Anything” on Reddit. This AMA gives you the opportunity to connect with Microsoft product experts who will be on hand to answer your questions and listen to feedback.

 

Feel free to post your questions for the DART team anytime in the comments below beforehand, if it fits your schedule or time zone better, though questions will not be answered until the live hour.

Trevor_Rusher
Updated Feb 16, 2022

57 Comments

    • aymansiraj's avatar
      aymansiraj
      Copper Contributor
      I think for most of us, it's figuring out a balance of how many hours to work a day during an incident as we will be going on for days when a customer is breached. We are humans, the customers defenders are human and sometimes someone needs to make the call on "Hey, we need to call it a night and give people rest!". Luckily, DART Leads are great at communicating to customer sponsors on the rotating and rest part of the incident.
    • eolson's avatar
      eolson
      Icon for Microsoft rankMicrosoft
      Probably one of the biggest challenges for me is there is almost ALWAYS something interesting going on and you want to be involved in all of it. So sometimes you have to take a pass on that one thing to give yourself time to take a breath.
    • DaveSchrock's avatar
      DaveSchrock
      Icon for Microsoft rankMicrosoft
      One of my biggest challenges was learning how to deliver good or bad news to a customer on their worst day. Ransomware may sometimes be less sophisticated then APT type activities, but the emotional drain and intensity is much higher. Learning how to speak clearly and accurately in these situations was a learning curve, but now its something I get excited about.
    • DaveSchrock's avatar
      DaveSchrock
      Icon for Microsoft rankMicrosoft
      This is a highly debated topic across the team. Some people are outright offended we even mention the thought of pineapple on pizza. Most of these people are located in Central Europe. Others are all about it and thrive on pushing the limits of the ordinary. There is no wrong answer here, as we will always order more than one pizza
    • rpeckham's avatar
      rpeckham
      Icon for Microsoft rankMicrosoft
      Pineapple tastes great with pineapple. There's nothing better. Unless it's on pizza! I'd pick it off and eat the pineapple solo.
  • aymansiraj's avatar
    aymansiraj
    Copper Contributor
    What does DART look for in new applicants? What tips does the team have for applicants and those interviewing?
    • kshitijk's avatar
      kshitijk
      Icon for Microsoft rankMicrosoft
      Passion for the subject matter (read: hunting adversaries, solving puzzles, helping customers) and willingness to learn (teachability and a self-starter mentality). Demonstrating critical thinking and storytelling skills also goes a long way!
    • eolson's avatar
      eolson
      Icon for Microsoft rankMicrosoft
      The best piece of advice I have ever been given by someone (who happened to work at Microsoft at the time) was to be yourself. You are what got you this far. It's okay to not know something and acknowledge it. I would rather someone not know than to make it up. If you put it on your resume, make sure you are ready to talk about it!
  • Trevor_Rusher's avatar
    Trevor_Rusher
    Icon for Community Manager rankCommunity Manager
    Welcome to the Microsoft Detection and Response Team (DART) Ask Microsoft Anything! This live hour gives you the opportunity to ask questions directly to the DART team. Please post any questions in a separate, new comment thread. To start this off on a friendly note, please introduce yourself on this post and tell us where you're logging in from!
  • cyberjanit0r's avatar
    cyberjanit0r
    Copper Contributor
    What recommendations does the DART team have regarding WSL2 detection logging for malicious activity and system hardening?
    • richarddavis2197's avatar
      richarddavis2197
      Icon for Microsoft rankMicrosoft
      Hi Nate, Pretty much the same as any Linux environment: minimize unnecessary services, harden accounts, etc. I know in September of 2021 there was a Russian malware variant that used a Linux loader (compiled Python) to inject into Windows processes -- it was quickly added to Defender and is now detected.
  • David_Caddick's avatar
    David_Caddick
    Brass Contributor
    Thanks Trevor,\nVery keen to hear how the DART Team get a handle on things from the outset - especially blocking Legacy Auth, Conditional Access and the like.\nRegards, Dave C
Date and Time
Mar 15, 20229:00 AM - 10:00 AM PDT