Sometimes we might come across samples of suspicious files which might be malicious. Sometimes, user will report such incident and you want to investigate in safe and proper way. In this case you don’t want malware to spread over network but you want to investigate it. In general, if you have Microsoft Defender ATP, they you could configure and investigate such incident easier. However, let say you don’t have MD ATP or for some reason, you could investigate it using MD ATP, then you have to follow these steps:
Handle the file correctly: make sure, you won’t open or execute the malicious object (e.g. file, registry…) and right click on it and all dependencies and make them as zip.
Investigate the source: Ask user how they encourage with the malware, behaviors which they believed it is malicious file and take a note of how it gets into PC (email, external device, …) and close the source (e.g. blacklist email, device ID, etc.).
Report to Microsoft: Once you are concern there is malicious object which won’t be detected with Windows Defender, submit sample of it to Microsoft Anti-Malware team and make sure add as much as details as possible under comment. In case, incident occurs in a system where is not in your access, ask user to submit sample and take note of submission URL, so you could trace status of analyze.
Update signature and enable cloud protection: In case of malware, in the analyze page, it will show which definition signature is able to remove it, make sure deploy the latest update on clients and meanwhile make sure cloud protection is on, so it will detect malwares while definition update is being deployed.