New Blog Post | What’s new: Fusion Detection for Ransomware

Microsoft

JasonCohen1892_0-1628530750953.png

Azure Sentinel Fusion Detection for Ransomware (microsoft.com)

In collaboration with the Microsoft Threat Intelligence Center (MSTIC), we are excited to announce Fusion detection for ransomware is now publicly available!

 

These Fusion detections correlate alerts that are potentially associated with ransomware activities that are observed at defense evasion and execution stages during a specific timeframe. Once such ransomware activities are detected and correlated by the Fusion machine learning model, a high severity incident titled “Multiple alerts possibly related to Ransomware activity detected” will be triggered in your Azure Sentinel workspace.

 

Original Post: New Blog Post | What’s new: Fusion Detection for Ransomware - Microsoft Tech Community

2 Replies

@JasonCohen1892  Any idea when this will get added to Azure Government?

Hey Dean,

Work is under way, but we do not have a specific ETA at the moment.