<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>rss.livelink.threads-in-node</title>
    <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/ct-p/microsoft-defender-for-endpoint</link>
    <description>rss.livelink.threads-in-node</description>
    <pubDate>Sat, 29 Aug 2026 09:54:38 GMT</pubDate>
    <dc:creator>microsoft-defender-for-endpoint</dc:creator>
    <dc:date>2026-08-29T09:54:38Z</dc:date>
    <item>
      <title>WDSI Submission Review Has Been Pending for 10 Days</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/wdsi-submission-review-has-been-pending-for-10-days/m-p/4549480#M6930</link>
      <description>&lt;P&gt;I submitted the application I developed to WDSI for review because the Microsoft Defender SmartScreen warning appears when running it. I would like the application to be added to the virus database so that this warning no longer appears, but the review has still not been completed after 10 days. Could you please help me?&lt;BR /&gt;&lt;BR /&gt;Submission ID: &amp;nbsp;61955163-f60b-4141-aafa-cd4afe171996&lt;BR /&gt;&lt;BR /&gt;Link: https://www.microsoft.com/en-us/wdsi/submission/61955163-f60b-4141-aafa-cd4afe171996&lt;/P&gt;</description>
      <pubDate>Mon, 24 Aug 2026 08:59:47 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/wdsi-submission-review-has-been-pending-for-10-days/m-p/4549480#M6930</guid>
      <dc:creator>Orxan</dc:creator>
      <dc:date>2026-08-24T08:59:47Z</dc:date>
    </item>
    <item>
      <title>Device* tables missing from Advanced Hunting schema despite M365 E5 license</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/device-tables-missing-from-advanced-hunting-schema-despite-m365/m-p/4545920#M6922</link>
      <description>&lt;P&gt;We have an M365 E5 trial (with Microsoft Defender for Endpoint service plan enabled) and a standalone Defender for Cloud Apps trial on the same tenant. Two devices are onboarded and show as Active in Device Inventory. &lt;STRONG&gt;one Windows 11 VM hosted on mac m4 &lt;/STRONG&gt;and one &lt;STRONG&gt;Windows Server 2019 Azure VM.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The issue: &lt;/STRONG&gt;the entire Devices section is missing from the Advanced Hunting schema. No DeviceInfo, DeviceNetworkEvents, DeviceEvents, DeviceProcessEvents, etc. The schema only shows Alerts &amp;amp; behaviors, Apps &amp;amp; identities, Email &amp;amp; collaboration, Defender Vulnerability Management, and Exposure Management.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Additionally:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;- The device Timeline tab does not appear on device pages (not in visible tabs or overflow menu)&lt;/P&gt;&lt;P&gt;- "Go hunt" from a device page only generates a query against IdentityLogonEvents,&amp;nbsp;&lt;STRONG&gt;not any Device* tables&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;img /&gt;&lt;P class="lia-clear-both"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;- Settings → Microsoft Defender XDR does not show an &lt;STRONG&gt;"Advanced hunting" &lt;/STRONG&gt;option for managing data sources&lt;/P&gt;&lt;img /&gt;&lt;P&gt;- The MDE Client Analyzer on the Azure VM passes all EDR cloud connectivity checks (CnC, Cyber, AutoIR, SampleUpload, MdeConfigMgr&amp;nbsp; all Succeeded 200)&lt;/P&gt;&lt;P&gt;- Settings → Endpoints → Optional features loads with all toggles including the Defender for Cloud Apps integration&lt;/P&gt;&lt;P&gt;- Cloud Discovery via MDA works (discovered apps visible on the device page)&lt;/P&gt;&lt;img /&gt;&lt;P&gt;- The Tenant ID and Org ID shown in XDR settings are different values&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The tenant originally had only the Defender for Cloud Apps standalone trial. The E5 trial was added afterward. It appears the MDE data source was never deployed/activated in Defender XDR despite the license and onboarding being in place.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've opened a support case&amp;nbsp; but wanted to ask here as well, has anyone resolved this issue? I've found several older posts describing the same problem but none with a confirmed fix.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any guidance would be appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2026 11:29:49 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/device-tables-missing-from-advanced-hunting-schema-despite-m365/m-p/4545920#M6922</guid>
      <dc:creator>rahman973</dc:creator>
      <dc:date>2026-08-11T11:29:49Z</dc:date>
    </item>
    <item>
      <title>How to send false positive?</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/how-to-send-false-positive/m-p/4544777#M6917</link>
      <description>&lt;P&gt;Hi, I coded a small program which Microsoft treats as malicous. Unfortunately the Microsoft false positive submission site is not working. How can I alternatively send a false positive to Microsoft? Any help is appreciated.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Aug 2026 18:15:09 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/how-to-send-false-positive/m-p/4544777#M6917</guid>
      <dc:creator>Joerg4</dc:creator>
      <dc:date>2026-08-06T18:15:09Z</dc:date>
    </item>
    <item>
      <title>EnableConvertWarnToBlock will not enable - stays False</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/enableconvertwarntoblock-will-not-enable-stays-false/m-p/4543965#M6912</link>
      <description>&lt;P&gt;We have a GPO applied to Windows 11 Pro machine - fully patched and onboarded to MDE. The GPO enables "EnableConvertWarnToBlock" as follows:&lt;/P&gt;&lt;img /&gt;&lt;P&gt;The GPO is applied to the machine and the following registry key is populated:&lt;/P&gt;&lt;img /&gt;&lt;P&gt;But when I check the status on the client - it will not enable:&lt;/P&gt;&lt;img /&gt;&lt;P&gt;I have enabled troubleshooting mode and disabled tamper protection in case this is blocking but nothing seems to work. Its as if MDAV/MDE is not even looking/reading that registry key.&lt;/P&gt;&lt;P&gt;Anyone else have the same issue or ideas on resolution?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2026 16:27:15 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/enableconvertwarntoblock-will-not-enable-stays-false/m-p/4543965#M6912</guid>
      <dc:creator>Warren212</dc:creator>
      <dc:date>2026-08-04T16:27:15Z</dc:date>
    </item>
    <item>
      <title>Location of Defender for Identity Entry in Defender Tables</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/location-of-defender-for-identity-entry-in-defender-tables/m-p/4543592#M6911</link>
      <description>&lt;P&gt;Our GRC group wants an automated report on windows servers and workstations over 7 days old not onboarded for Defender for Endpoint. A change in our environment (not sure if it was MS or us) has caused an additional entry in a column named "DiscoverySources" for Defender for Identity. It's my understanding that D4I is only used on domain controllers, but we get entries on non-DCs as well.&amp;nbsp; This identifier does not appear on the device dashboard, nor can I add it in with the custom column tab. Furthermore, if a machine requires onboarding for D4E, it will show them both in the same column, it separates them with a comma in the same field.&lt;/P&gt;&lt;P&gt;Right now, I have to do this process manually and with the overhead involved, it takes me about 30 minutes to run the reports, filter out the false positives and forward them to the appropriate staff.&amp;nbsp; They want this every day, and I can't do this operationally. I'd welcome the opportunity to create a Logic App based on a query to perform this function and route it.&lt;/P&gt;&lt;P&gt;Can someone point me in the direction of the table which contains the DiscoverSources column? I haven't been able to find it. That would help me to perform the necessary KQL and Logic App to automate this process.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Long time listener. First time publisher. Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2026 18:39:16 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/location-of-defender-for-identity-entry-in-defender-tables/m-p/4543592#M6911</guid>
      <dc:creator>MichaelMichalko</dc:creator>
      <dc:date>2026-08-03T18:39:16Z</dc:date>
    </item>
    <item>
      <title>Defender Device Groups</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/defender-device-groups/m-p/4542535#M6908</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;I need some help creating a device group in Defender. I can't find anything related to Groups inside Microsoft Security. I'd read that it's possible to create one inside the Permissions tab, but I can't figure out how.&lt;/P&gt;&lt;P&gt;Someone can explain what's the process?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;img /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2026 20:59:40 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/defender-device-groups/m-p/4542535#M6908</guid>
      <dc:creator>alexcolombari</dc:creator>
      <dc:date>2026-07-30T20:59:40Z</dc:date>
    </item>
    <item>
      <title>Inconsistent Microsoft Defender Behaviour</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/inconsistent-microsoft-defender-behaviour/m-p/4538802#M6904</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;We have an issue whereby across several intune managed devices with identical defender AV policy, signature version, and platform version, we've found inconsistent detection/remediation behaviour.&lt;/P&gt;&lt;P&gt;Some devices block malicious files instantly on download (expected and correct). Others only detect on open rather than on write, or log a successful detection/remediation action without the file actually being removed from disk, it remains fully accessible indefinitely.&lt;/P&gt;&lt;P&gt;Since this occurs despite identical config, we're concerned this is a genuine gap in automatic remediation reliability that could affect real threats, not just our test files.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Troubleshooting completed, issue persists:&lt;/P&gt;&lt;P&gt;- Ruled out exclusions (path/extension/process)&lt;/P&gt;&lt;P&gt;- Confirmed PUA protection, real-time protection, tamper protection, and all granular protection flags enabled/healthy&lt;/P&gt;&lt;P&gt;- Removed orphaned third-party AV registrations from WSC (previously caused Defender to show as "snoozed")&lt;/P&gt;&lt;P&gt;- Confirmed filter driver (WdFilter) loaded correctly, no conflicts&lt;/P&gt;&lt;P&gt;- Cleared stuck "detected but not remediated" threat entries&lt;/P&gt;&lt;P&gt;- Ruled out file locks preventing remediation&lt;/P&gt;&lt;P&gt;- Cleared cached signature state, forced fresh signature pull&lt;/P&gt;&lt;P&gt;- Attempted full platform reset&lt;/P&gt;&lt;P&gt;- Confirmed cloud protection/MAPS enabled and reachable&lt;/P&gt;&lt;P&gt;- Increased CloudBlockLevel to test enforcement aggressiveness&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone have any idea what could be happening here?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2026 07:54:38 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/inconsistent-microsoft-defender-behaviour/m-p/4538802#M6904</guid>
      <dc:creator>OllieHay1</dc:creator>
      <dc:date>2026-07-20T07:54:38Z</dc:date>
    </item>
    <item>
      <title>MDVM - Patch Publication Date</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/mdvm-patch-publication-date/m-p/4537884#M6902</link>
      <description>&lt;P&gt;Dear Microsoft MDVM Development Team,&lt;/P&gt;&lt;P&gt;Please could you as quickly as possible implement the "Patch Publication Date" for the vulnerabilities you report on. Any major Vulnerability management platform has this simple field/record please advise you are implementing this and the timeframe for it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards,&lt;/P&gt;&lt;P&gt;Graeme&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2026 14:54:25 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/mdvm-patch-publication-date/m-p/4537884#M6902</guid>
      <dc:creator>cipherdell</dc:creator>
      <dc:date>2026-07-16T14:54:25Z</dc:date>
    </item>
    <item>
      <title>New Privileged Token Context Telemetry Boosts Advanced Hunting in Microsoft Defender</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/new-privileged-token-context-telemetry-boosts-advanced-hunting/ba-p/4528613</link>
      <description>&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;In brief:&lt;/STRONG&gt;&amp;nbsp;Defenders can now easily identify &lt;STRONG&gt;logons involving high-privilege identities or special logon flags&lt;/STRONG&gt; to better hunt threats and fine-tune detections.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;When a user logs on, Windows’&amp;nbsp;&lt;STRONG&gt;Local Security Authority (LSA)&lt;/STRONG&gt;&amp;nbsp;constructs an&amp;nbsp;&lt;STRONG&gt;access token &lt;/STRONG&gt;that represents the user’s security context for that session. This token includes the &lt;STRONG&gt;user’s SID, group memberships, user rights, and logon flags&lt;/STRONG&gt;, the information that determines what the session is allowed to access. The challenge was that, although Microsoft Defender has been collecting a token creation event at logon to supplement standard logon telemetry, the most important &lt;STRONG&gt;privilege context&lt;/STRONG&gt; inside that token was not directly exposed for hunting. It was possible to see that a logon occurred, but much harder to quickly answer questions like: &lt;EM&gt;Did this session include Domain Admin membership? Was the logon tied to a local account?&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We’re excited to share that Microsoft Defender is closing this visibility gap by surfacing key privilege context from token creation events that occur during login. It surfaces these&amp;nbsp;&lt;STRONG&gt;new token context fields in Advanced Hunting&lt;/STRONG&gt;, making it possible to query the privileged groups and logon attributes that were present in the user’s token &lt;STRONG&gt;at logon time&lt;/STRONG&gt;. With this context available directly in hunting data, it is now much easier to isolate privileged sessions, investigate suspicious logons, and build higher-fidelity detections around privilege misuse.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;New fields include:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;TokenHasDomainAdminSid&lt;/STRONG&gt;&amp;nbsp;-&amp;nbsp;The token contained the&amp;nbsp;&lt;STRONG&gt;Domain Admins&lt;/STRONG&gt;&amp;nbsp;group SID.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;TokenHasSchemaAdminSid &lt;/STRONG&gt;-&lt;STRONG&gt; &lt;/STRONG&gt;The token contained the &lt;STRONG&gt;Schema Admins&lt;/STRONG&gt; group SID.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;TokenHasEnterpriseAdminSid &lt;/STRONG&gt;- The token contained the &lt;STRONG&gt;Enterprise Admins&lt;/STRONG&gt; group SID.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;TokenHasGroupPolicyCreatorSid &lt;/STRONG&gt;- The token contained the &lt;STRONG&gt;Group Policy Creator Owners&lt;/STRONG&gt; group SID.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;TokenHasDomainControllerSid&lt;/STRONG&gt;&amp;nbsp;- The token contained the&amp;nbsp;&lt;STRONG&gt;Domain Controllers&lt;/STRONG&gt;&amp;nbsp;group SID (indicates a DC’s computer account logon).&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;TokenHasCertificatePublisherSid&lt;/STRONG&gt;&amp;nbsp;- The token contained the&amp;nbsp;&lt;STRONG&gt;Certificate Publishers&lt;/STRONG&gt;&amp;nbsp;group SID (relevant in AD Certificate Services scenarios).&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;TokenHasLocalAccountSid&lt;/STRONG&gt;&amp;nbsp;- The token contained a&amp;nbsp;&lt;STRONG&gt;local account SID&lt;/STRONG&gt; (not a domain account).&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;TokenHasNtlmAuthSid&lt;/STRONG&gt;&amp;nbsp;- The token contained the&amp;nbsp;&lt;STRONG&gt;NTLM authentication SID&lt;/STRONG&gt; (rather than Kerberos).&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;TokenHasThisOrgCertificateSid&lt;/STRONG&gt;&amp;nbsp;- The token contained a SID associated with&amp;nbsp;&lt;STRONG&gt;certificate-based authentication issued by the organization&lt;/STRONG&gt; (e.g., PKINIT logon).&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;NumberOfSidsInDomainAdminToken&lt;/STRONG&gt;&amp;nbsp;- If the token contained the &lt;STRONG&gt;Domain Admins&lt;/STRONG&gt;&amp;nbsp;group SID, this represents the&amp;nbsp;&lt;STRONG&gt;total number of SIDs&lt;/STRONG&gt;&amp;nbsp;in that token (a measure of how many group memberships/privileges/logon flags were in an admin’s token).&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;These fields are available under&amp;nbsp;&lt;STRONG&gt;AdditionalFields&lt;/STRONG&gt;&amp;nbsp;in the&amp;nbsp;&lt;STRONG&gt;DeviceLogonEvents&lt;/STRONG&gt; table.&lt;/P&gt;
&lt;img /&gt;
&lt;H4&gt;How it works&lt;/H4&gt;
&lt;P&gt;Defender is&amp;nbsp;&lt;STRONG&gt;deriving these fields from the token’s SID list&lt;/STRONG&gt;&amp;nbsp;at the moment of logon. Essentially, when the access token is created, Defender inspects it for any &lt;STRONG&gt;well-known high-privilege SIDs or special logon flags&lt;/STRONG&gt; (see &lt;A href="https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-dtyp/81d92bba-d22b-4a8c-908a-554ab29148ab" target="_blank" rel="noopener"&gt;[MS-DTYP]: Well-Known SID Structures | Microsoft Learn&lt;/A&gt; for reference). By capturing privileges&amp;nbsp;&lt;STRONG&gt;at token creation&lt;/STRONG&gt;, the data offers an&amp;nbsp;&lt;STRONG&gt;accurate snapshot of the user’s rights at logon&lt;/STRONG&gt;. This is valuable because it can&amp;nbsp;&lt;STRONG&gt;catch ephemeral privilege elevations.&lt;/STRONG&gt; For example, whether an account is temporarily added to an admin group and quickly removed, or an attacker manipulates the PAC directly using a Silver or Golden Ticket, any logon during that window will still contain the admin SID in the token, even if the directory no longer reflects that membership later.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Note:&lt;/EM&gt;&lt;/STRONG&gt;&lt;EM&gt;&amp;nbsp;This token context telemetry is&amp;nbsp;&lt;STRONG&gt;additive&lt;/STRONG&gt;&amp;nbsp;to existing Windows logon events. Standard Security Log events like&amp;nbsp;&lt;STRONG&gt;4624 (logon success)&lt;/STRONG&gt;&amp;nbsp;provide information on network context (source IP, etc.) but don’t tell you about group memberships or special authentication methods. The new token fields fill that gap by focusing on&amp;nbsp;&lt;STRONG&gt;privilege context&lt;/STRONG&gt;. To correlate a token event with a traditional logon event and obtain a more complete view of the logon, you can match common attributes such as timestamp, account SID, device, logon type and logon ID (see the example query under “1. Spot suspicious privileged logons” below). Together, the two sources let you understand both&amp;nbsp;&lt;STRONG&gt;how&lt;/STRONG&gt;&amp;nbsp;the logon happened and&amp;nbsp;&lt;STRONG&gt;what privileges&lt;/STRONG&gt; it carried.&lt;/EM&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H4&gt;Why this is powerful for defenders&lt;/H4&gt;
&lt;P&gt;The new token context fields unlock powerful ways to&amp;nbsp;&lt;STRONG&gt;detect misuse of privileged accounts and unusual authentication patterns&lt;/STRONG&gt;. For example:&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;1. Spot suspicious privileged logons&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;Identify&amp;nbsp;cases where privileged tokens appear in unexpected contexts&amp;nbsp;(e.g., admin accounts logging into low-tier devices, unusual logon types, or rare hosts).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang=""&gt;// Token creation events
let TokenCreateEvents =
DeviceLogonEvents
| where InitiatingProcessFileName == "lsass.exe" // Token creation events
| where AdditionalFields has "TokenHasDomainAdminSid"
| project DeviceId, AccountSid, AccountDomain, AccountName, LogonType, LogonId,
          AdditionalFields, TokenTime = Timestamp;
// Standard logon events
DeviceLogonEvents
| where ActionType == "LogonSuccess"
| where InitiatingProcessFileName != "lsass.exe"  // filter out Token creation events
| project DeviceId, AccountSid, AccountDomain, AccountName, LogonType, LogonId,
          RemoteDeviceName, RemoteIP, Timestamp
// Correlate both events (same logon, small time window)
| join kind=inner TokenCreateEvents on DeviceId, AccountSid, AccountDomain, AccountName, LogonType, LogonId
| where Timestamp between (TokenTime - 1s .. TokenTime + 1s)
// Example filter (specific source device)
| where RemoteDeviceName == "kali"&lt;/LI-CODE&gt;
&lt;H5&gt;&lt;STRONG&gt;2. Detect privilege escalation attempts&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;As previously detailed, whether an adversary utilizes ephemeral group modifications or direct PAC manipulation, the outcome is the same. These temporary group memberships used during an attack will still be reflected in the token captured at logon, making this activity easier to identify retrospectively. For instance, a standard user who suddenly logs on with&amp;nbsp;TokenHasDomainAdminSid is a&amp;nbsp;&lt;STRONG&gt;red flag&lt;/STRONG&gt;&amp;nbsp;for potential&amp;nbsp;&lt;STRONG&gt;token manipulation or group membership abuse&lt;/STRONG&gt;.&lt;STRONG&gt; &lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;LI-CODE lang=""&gt;let lookback = 14d;
let recent = 1d;
let token_priv = "TokenHasDomainAdminSid";
// Baseline: users who historically were DAs
let baseline_users =
DeviceLogonEvents
| where Timestamp between (ago(lookback) .. ago(recent))
| where InitiatingProcessFileName == "lsass.exe" // Token creation events
| summarize DA_sids = make_set_if(AccountSid, AdditionalFields has token_priv),
            non_DA_sids = make_set_if(AccountSid, AdditionalFields !has token_priv);
// Recent: new users with DA token
DeviceLogonEvents
| where Timestamp &amp;gt; ago(recent)
| where AdditionalFields has token_priv
| where AccountSid in (baseline_users | project non_DA_sids) and
        AccountSid !in (baseline_users | project DA_sids)&lt;/LI-CODE&gt;
&lt;H5&gt;&lt;STRONG&gt;3. Monitor certificate-based logons&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;If your environment does not normally use smart cards or certificate-based authentication, or if a user who does not typically authenticate using smart cards suddenly generates events with &lt;STRONG&gt;TokenHasThisOrgCertificateSid&lt;/STRONG&gt;, this may warrant investigation, as it could indicate authentication using a fraudulently issued certificate.&lt;STRONG&gt; &lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;LI-CODE lang=""&gt;let lookback = 14d;
let recent = 1d;
// Baseline: users who historically used certificate-based auth
let baseline_users =
DeviceLogonEvents
| where Timestamp between (ago(lookback) .. ago(recent))
| where AdditionalFields has "TokenHasThisOrgCertificateSid"
| summarize by AccountSid;
// Recent: new certificate-based logons
DeviceLogonEvents
| where Timestamp &amp;gt; ago(recent)
| where AdditionalFields has "TokenHasThisOrgCertificateSid"
| where AccountSid !in (baseline_users)&lt;/LI-CODE&gt;
&lt;H5&gt;&lt;STRONG&gt;&amp;nbsp;4. &lt;/STRONG&gt;&lt;STRONG style="color: rgb(30, 30, 30);"&gt;Identify local account lateral movement&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;Pivot on &lt;STRONG&gt;TokenHasLocalAccountSid&lt;/STRONG&gt; to identify logons where a &lt;STRONG&gt;local account&lt;/STRONG&gt; was used, especially in &lt;STRONG&gt;remote or network logon scenarios&lt;/STRONG&gt;. Such activity is uncommon in well-managed environments and may indicate lateral movement using shared credentials or local administrator reuse.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang=""&gt;DeviceLogonEvents
| where Timestamp &amp;gt; ago(7d)
| where AdditionalFields has "TokenHasLocalAccountSid"
| where LogonType == "Network" or LogonType == "RemoteInteractive"&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;These examples illustrate how token privilege context can improve both threat hunting and detection engineering. Analysts can quickly isolate high-interest logons from large volumes of authentication telemetry, while custom detection rules can leverage these fields to focus on sessions with elevated privileges and improve fidelity.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2026 16:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/new-privileged-token-context-telemetry-boosts-advanced-hunting/ba-p/4528613</guid>
      <dc:creator>TalTzhori</dc:creator>
      <dc:date>2026-07-15T16:00:00Z</dc:date>
    </item>
    <item>
      <title>DVM Certificate Inventory Shows No Data Despite Healthy Endpoints in Defender for Endpoint</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/dvm-certificate-inventory-shows-no-data-despite-healthy/m-p/4534494#M6897</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;I'm testing Microsoft Defender Vulnerability Management.&lt;/P&gt;&lt;P&gt;Current status:&lt;/P&gt;&lt;P&gt;- Defender Vulnerability Management Add-on enabled&lt;/P&gt;&lt;P&gt;- Certificates inventory tab is visible&lt;/P&gt;&lt;P&gt;- Software Inventory populated&lt;/P&gt;&lt;P&gt;- Security Recommendations populated&lt;/P&gt;&lt;P&gt;- Windows and Linux devices onboarded&lt;/P&gt;&lt;P&gt;- Linux mdatp health = healthy:true, licensed:true, cloud_enabled:true&lt;/P&gt;&lt;P&gt;- Devices have local certificates installed&lt;/P&gt;&lt;P&gt;- Certificate Inventory page shows "No data"&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;The DVM Add-on was enabled more than 36 hours ago.&lt;/P&gt;&lt;P&gt;Has anyone experienced a delay in Certificate Inventory population or are there additional prerequisites beyond DVM licensing and device onboarding?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2026 12:54:31 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/dvm-certificate-inventory-shows-no-data-despite-healthy/m-p/4534494#M6897</guid>
      <dc:creator>vijaysethiya</dc:creator>
      <dc:date>2026-07-07T12:54:31Z</dc:date>
    </item>
    <item>
      <title>Microsoft Defender false positive and WDSI submission details page bug</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/microsoft-defender-false-positive-and-wdsi-submission-details/m-p/4530787#M6892</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am the developer and publisher of Pulse Launcher, a legitimate signed Windows application / Minecraft mod launcher.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I already submitted this through Microsoft Security Intelligence and also opened a Microsoft Q&amp;amp;A thread, but I am posting here because the WDSI submission portal itself appears to be broken for these submissions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Related Microsoft Q&amp;amp;A thread:&lt;/P&gt;&lt;P&gt;https://learn.microsoft.com/en-us/answers/questions/5929545/microsoft-defender-false-positive-and-wdsi-submiss&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are two related issues:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Microsoft Defender cloud ML false positives keep appearing on public multi-engine scan results for the same signed application/product family. The Microsoft detection name changes across rescans and equivalent builds, including:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- PUA:Win32/Puwaders.C!ml&lt;/P&gt;&lt;P&gt;- Program:Win32/Wacapew.C!ml&lt;/P&gt;&lt;P&gt;- Trojan:Win32/Wacatac.B!ml&lt;/P&gt;&lt;P&gt;- Trojan:Win32/Wacatac.C!ml&lt;/P&gt;&lt;P&gt;- Trojan:Win32/Sabsik.EN.A!ml&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. Microsoft Security Intelligence submissions are visible in Submission history and show status "In progress", but opening the submission details page returns:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"The details for the submission were not found or the submission has expired."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Affected submission IDs:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- dd476efa-fc04-4f13-82cf-631bbfd145a6&lt;/P&gt;&lt;P&gt;- efc6514c-d700-4d6a-a7e2-67a9a83334a2&lt;/P&gt;&lt;P&gt;- ff8d04b7-c5fc-4a05-bd53-ee7ac5981284&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;File details:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- File name: pulse_launcher.exe&lt;/P&gt;&lt;P&gt;- SHA-256: def6059c07c3e1f4a8c5649a1bbf190d4f355ee8e8b88c55c5b404edee99ecc8&lt;/P&gt;&lt;P&gt;- Signer: FOP Haponiuk Mykola Viktorovych&lt;/P&gt;&lt;P&gt;- Certificate: GlobalSign EV Code Signing certificate&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The executable is not VMProtect-packed or obfuscated. It is EV-signed. A previous Microsoft analyst response stated that the file did not meet Microsoft criteria for malware or PUA, but Microsoft cloud detections continue to appear.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could someone route this to Microsoft Defender Security Intelligence / malware analysis, or advise how to escalate WDSI submissions that exist in history but whose details endpoint returns "not found or expired"?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2026 02:56:05 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/microsoft-defender-false-positive-and-wdsi-submission-details/m-p/4530787#M6892</guid>
      <dc:creator>MykolaHaponiuk</dc:creator>
      <dc:date>2026-06-25T02:56:05Z</dc:date>
    </item>
    <item>
      <title>Microsoft Defender for Endpoint and WDAC audit logs not include kernel audit/blocks</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/microsoft-defender-for-endpoint-and-wdac-audit-logs-not-include/m-p/4527862#M6885</link>
      <description>&lt;P&gt;While testing WDAC on a fully patched Win11 pro machine - I noticed that kernel audit/block events do not get collected by MDE in the advanced hunting portal, only user mode audit/blocks are collected. Can anyone confirm they see this too and is this by design?&lt;/P&gt;&lt;P&gt;My test case is to use a Strict Kernel Mode WDAC policy (as per:&lt;/P&gt;&lt;P&gt;https://github.com/HotCakeX/Harden-Windows-Security/wiki/WDAC-policy-for-BYOVD-Kernel-mode-only-protection) which is active, using the global secure access client as my test, when the machine boots, the below event is generated locally on the machine:&amp;nbsp;&lt;/P&gt;&lt;img /&gt;&lt;img /&gt;&lt;img /&gt;&lt;P&gt;This event is never shown on the MDE advanced hunting portal, though user events do show. Examples of events that are coming through:&lt;/P&gt;&lt;img /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not receiving these events centrally for auditing would make deploying a kernel mode wdac control impossible. Would be amazing if Microsoft product team could look into this and resolve as these alerts should be captured as well please to facilitate deployment of more secure controls.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jun 2026 13:35:02 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/microsoft-defender-for-endpoint-and-wdac-audit-logs-not-include/m-p/4527862#M6885</guid>
      <dc:creator>Warren212</dc:creator>
      <dc:date>2026-06-12T13:35:02Z</dc:date>
    </item>
    <item>
      <title>Reduce unnecessary internet exposure with Microsoft Defender</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/reduce-unnecessary-internet-exposure-with-microsoft-defender/ba-p/4525654</link>
      <description>&lt;P&gt;In today’s threat landscape, &lt;STRONG&gt;internet exposure&lt;/STRONG&gt;, i.e. devices that allow inbound connectivity from the public internet, continues to be a major vector for initial access and compromise. Devices that are exposed to the public internet can significantly increase an organization’s attack surface, making them prime targets for initial access, exploitation, and lateral movement.&lt;/P&gt;
&lt;P&gt;However, not all internet-facing devices represent a security issue. Many are intentionally exposed to support business-critical scenarios such as hosting web applications, enabling remote access, or supporting communication services. The challenge for security teams is not just detecting internet-facing devices, but understanding why a device is exposed, whether that exposure is expected, and what action should be taken. That’s why we’re introducing a&amp;nbsp;&lt;STRONG&gt;new security recommendation in Microsoft Defender that helps organizations&lt;/STRONG&gt; &lt;STRONG&gt;identify, review, and reduce unnecessary internet exposure across their environment.&lt;/STRONG&gt;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Understand your internet-facing exposure&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;This recommendation focuses specifically on devices that are &lt;STRONG&gt;accessible from the public internet&lt;/STRONG&gt;, meaning they can receive &lt;STRONG&gt;inbound connections initiated from external sources, &lt;/STRONG&gt;not devices that only use the internet for outbound communication.&lt;/P&gt;
&lt;P&gt;Externally reachable assets are often the first point of entry for attackers, making this a critical signal for security prioritization.&lt;/P&gt;
&lt;P&gt;Microsoft Defender identifies internet-facing devices based on signals that indicate &lt;STRONG&gt;external inbound reachability&lt;/STRONG&gt;, including:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;External scan telemetry identifying devices reachable from the public internet&lt;/LI&gt;
&lt;LI&gt;Network telemetry showing inbound connections from external sources&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;By correlating these signals, Defender surfaces devices that are externally reachable.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Introducing internet-facing exposure assessment&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;A new recommendation in Microsoft Defender provides a centralized view of devices that are externally reachable from the public internet, helping you understand and manage exposure across your environment.&lt;/P&gt;
&lt;P&gt;This assessment categorizes devices based on their exposure state:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Exposed devices: Devices that are reachable from the public internet and require review&lt;/LI&gt;
&lt;LI&gt;Compliant devices: Devices that are not externally reachable, or where the internet exposure has been explicitly validated and accepted by the organization’s security team as intended&lt;/LI&gt;
&lt;LI&gt;Not applicable devices: Devices that do not exhibit inbound internet exposure&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;From the recommendation view, you can:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Drill down into exposed devices and understand why they are reachable&lt;/LI&gt;
&lt;LI&gt;Review context such as exposed services and connectivity&lt;/LI&gt;
&lt;LI&gt;Explore device-level details to support investigation&lt;/LI&gt;
&lt;LI&gt;Track exposure posture across your environment over time&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;&lt;STRONG&gt;Take action on your internet exposure&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;To access this recommendation in the Defender portal, navigate to &lt;STRONG&gt;Exposure management → Recommendations → Devices → Misconfigurations&lt;/STRONG&gt;. Once Defender identifies internet-facing devices, it provides the context needed to review and take action.&lt;/P&gt;
&lt;H5&gt;Your action plan&lt;/H5&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;1. Assess your exposure&lt;/STRONG&gt;&lt;BR /&gt;Review the recommendation to understand which devices in your environment are externally reachable from the public internet and why they were classified as internet-facing.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;2. Validate whether exposure is required&lt;/STRONG&gt;&lt;BR /&gt;Determine if the inbound connectivity is expected for each device. Confirm business need and ownership before taking action.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;3. Prioritize high-risk assets&lt;/STRONG&gt;&lt;BR /&gt;Focus on critical servers or sensitive environments that are exposed to the internet, as they present the highest risk for initial access.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;4. Reduce unnecessary exposure&lt;/STRONG&gt;&lt;BR /&gt;Restrict or remove inbound connectivity where it is not required by closing exposed ports, removing public access, or moving services behind controlled access layers.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;5. Track and maintain posture over time&lt;/STRONG&gt;&lt;BR /&gt;Continuously monitor internet-facing devices to ensure unnecessary exposure is reduced and new exposure is validated as environments evolve.&lt;/P&gt;
&lt;H5&gt;FAQ&lt;/H5&gt;
&lt;P&gt;&lt;STRONG&gt;1. Which devices are currently supported?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;This recommendation applies to supported Windows client and Windows Server devices. Supported versions include Windows 10, version 1607 and earlier; Windows 10, version 1809 and later; and Windows 11.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;2. Why might there be differences between this recommendation and the Internet-facing filter in device inventory?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;This recommendation reflects devices observed as internet-facing during the recommendation assessment window. Device exposure can change over time, and different Microsoft Defender experiences may refresh at different times.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;As a result, temporary differences may occur between this recommendation and the Internet-facing filter in device inventory.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;For the most current device-level view, use the Internet-facing filter in device inventory. If a device was recently remediated or its exposure recently changed, allow time for the recommendation status to refresh.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;3. Could regular employee laptops or personal devices appear as internet-facing?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;This recommendation evaluates supported devices onboarded to Microsoft Defender for Endpoint and focuses specifically on inbound internet reachability.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;Typical internet usage, such as web browsing, generates outbound traffic and does not by itself classify a device as internet-facing.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;Devices are identified as internet-facing only when they are externally reachable from the public internet.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;As a result:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;UL&gt;
&lt;LI&gt;Personal devices that are not onboarded to Microsoft Defender for Endpoint are not included in this assessment.&lt;/LI&gt;
&lt;LI&gt;Corporate laptops may appear as internet-facing if they are directly reachable from the internet, which may indicate an unintended network exposure or configuration issue.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;&lt;STRONG&gt;Learn more&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;For additional guidance on investigating and managing internet-facing devices, see:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Learn how Defender identifies and maps externally reachable devices across your environment &lt;A href="https://techcommunity.microsoft.com/blog/microsoftdefenderatpblog/discovering-internet-facing-devices-using-microsoft-defender-for-endpoint/3778975" target="_blank" rel="noopener"&gt;Discovering internet-facing devices using Microsoft Defender&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Learn how to review and investigate internet-facing device exposure &lt;A href="https://learn.microsoft.com/en-us/defender-endpoint/investigate-machines" target="_blank" rel="noopener"&gt;Investigate devices in Microsoft Defender&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Learn more about&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-microsoft-secure-score-devices?tabs=preview-customers" target="_blank" rel="noopener"&gt;Microsoft Secure Score for Devices in Microsoft Defender&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;To learn more about endpoint protection with Microsoft Defender, check out our&amp;nbsp;&lt;A href="https://www.microsoft.com/security/business/endpoint-security/microsoft-defender-endpoint" target="_blank" rel="noopener"&gt;website&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;To learn more about Microsoft Security solutions, visit our&amp;nbsp;&lt;A href="https://www.microsoft.com/en-us/security/business" target="_blank" rel="noopener"&gt;website.&lt;/A&gt;&amp;nbsp;Bookmark the&amp;nbsp;&lt;A href="https://www.microsoft.com/security/blog/" target="_blank" rel="noopener"&gt;Security blog&lt;/A&gt;&amp;nbsp;to keep up with our expert coverage on security matters. Follow us on LinkedIn (&lt;A href="https://www.linkedin.com/showcase/microsoft-security/" target="_blank" rel="noopener"&gt;Microsoft Security&lt;/A&gt;) and X (&lt;A href="https://twitter.com/@MSFTSecurity" target="_blank" rel="noopener"&gt;@MSFTSecurity&lt;/A&gt;)&amp;nbsp;for the latest news and updates on cybersecurity.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 11 Jun 2026 16:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/reduce-unnecessary-internet-exposure-with-microsoft-defender/ba-p/4525654</guid>
      <dc:creator>hadarshindler</dc:creator>
      <dc:date>2026-06-11T16:00:00Z</dc:date>
    </item>
    <item>
      <title>Introducing scheduled antivirus scans on Microsoft Defender Linux</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/introducing-scheduled-antivirus-scans-on-microsoft-defender/ba-p/4524578</link>
      <description>&lt;P&gt;Security teams rely on scheduled scans to ensure consistent coverage across devices, detect dormant or missed threats, and meet compliance requirements. However, managing scans on Linux has traditionally required custom scripts and cron-based setups, which can be hard to scale and maintain. That’s why we’re excited to introduce &lt;STRONG&gt;centrally managed scheduled antivirus scans for Linux in Microsoft Defender&lt;/STRONG&gt;. With this release, we are bringing built-in, flexible scheduling capabilities directly into Defender - making it easier to manage and standardize scan behavior across Linux environments.&lt;/P&gt;
&lt;H4&gt;What’s new&lt;/H4&gt;
&lt;P&gt;With this capability, customers can now configure scheduled antivirus scans on Linux using &lt;STRONG&gt;security settings management policies in the Microsoft Defender portal&lt;/STRONG&gt; for centralized policy enforcement or &lt;STRONG&gt;local Managed JSON configuration&lt;/STRONG&gt; that can be deployed via configuration management tools like ansible, puppet and chef.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The feature supports a flexible set of scheduling options, including &lt;STRONG&gt;hourly quick scans&lt;/STRONG&gt; (interval-based scheduling), &lt;STRONG&gt;daily quick scans&lt;/STRONG&gt; at a defined time, and &lt;STRONG&gt;weekly scans&lt;/STRONG&gt; with configurable scan type (quick or full). In addition, customers can control how scans run with advanced options such as:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Running scans only when the device is idle&lt;/LI&gt;
&lt;LI&gt;Reducing CPU impact using low CPU priority&lt;/LI&gt;
&lt;LI&gt;Checking for definition updates before scanning&lt;/LI&gt;
&lt;LI&gt;Randomizing scans start times&lt;/LI&gt;
&lt;LI&gt;Ignoring exclusions during scheduled scans&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;These capabilities allow security teams to balance &lt;STRONG&gt;coverage, performance, and operational needs&lt;/STRONG&gt; across large Linux environments.&lt;/P&gt;
&lt;H4&gt;Why this matters&lt;/H4&gt;
&lt;P&gt;From a security perspective, scheduled scans play a critical role in detecting &lt;STRONG&gt;dormant threats, missed detections, and malicious artifacts&lt;/STRONG&gt; that may not be caught through real-time protection alone. Without consistent and centrally enforced scheduling, these gaps can increase risk across the environment.&lt;/P&gt;
&lt;P&gt;With this release, scheduled scans are now:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Centrally managed&lt;/STRONG&gt; through Defender policies&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Consistently enforced&lt;/STRONG&gt; across devices&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Aligned with security best practices&lt;/STRONG&gt; for regular scanning&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Integrated into the broader Defender security posture&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This helps organizations strengthen their overall security posture while reducing operational complexity.&lt;/P&gt;
&lt;H4&gt;Get started&lt;/H4&gt;
&lt;P&gt;To get started, ensure devices are running &lt;STRONG&gt;agent version 101.26032.0000 or later (production ring)&lt;/STRONG&gt;, and configure scheduled scans using managed JSON or Defender portal policies.&lt;/P&gt;
&lt;H4&gt;Learn more&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;Learn more about how to &lt;A href="https://learn.microsoft.com/en-us/defender-endpoint/schedule-antivirus-scans-linux" target="_blank" rel="noopener"&gt;schedule antivirus scans on Linux&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI&gt;To learn more about endpoint protection with Microsoft Defender, check out our&amp;nbsp;&lt;A href="https://www.microsoft.com/security/business/endpoint-security/microsoft-defender-endpoint" target="_blank" rel="noopener"&gt;website&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;To learn more about Microsoft Security solutions, visit our &lt;A href="https://www.microsoft.com/en-us/security/business" target="_blank" rel="noopener"&gt;website.&lt;/A&gt; Bookmark the &lt;A href="https://www.microsoft.com/security/blog/" target="_blank" rel="noopener"&gt;Security blog&lt;/A&gt; to keep up with our expert coverage on security matters. Follow us on LinkedIn (&lt;A href="https://www.linkedin.com/showcase/microsoft-security/" target="_blank" rel="noopener"&gt;Microsoft Security&lt;/A&gt;) and X (&lt;A href="https://twitter.com/@MSFTSecurity" target="_blank" rel="noopener"&gt;@MSFTSecurity&lt;/A&gt;) for the latest news and updates on cybersecurity.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 15 Jul 2026 14:05:55 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/introducing-scheduled-antivirus-scans-on-microsoft-defender/ba-p/4524578</guid>
      <dc:creator>Rutuja_dange</dc:creator>
      <dc:date>2026-07-15T14:05:55Z</dc:date>
    </item>
    <item>
      <title>Elevate your telemetry using custom data collection in Microsoft Defender</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/elevate-your-telemetry-using-custom-data-collection-in-microsoft/ba-p/4512530</link>
      <description>&lt;P&gt;At Ignite in November, we announced that Microsoft Defender is now the only endpoint protection solution that allows data-hungry security teams to meet specific telemetry needs by optimizing their data collection right within the Defender portal, without the need to rely on fragmented and siloed solutions. Since then, we've heard from customers that this tool has been a game changer, enabling them to hunt through new data types as well as richer data on events already reported. The release of custom data collection was a key milestone in our ongoing journey to make Defender easy to manage and customize.&lt;/P&gt;
&lt;P&gt;Security teams have been asking for guidance and examples of how to get the most out of the tool, so today we're sharing how some organizations can use custom data collection and dynamic tagging to detect command and control (C2) communications, giving defenders elevated visibility and deeper telemetry into attacker activity across the environment.&lt;/P&gt;
&lt;H4&gt;See the data you want to see&lt;/H4&gt;
&lt;P&gt;Defender's default telemetry is tuned to balance performance and signal-to-noise across millions of devices, so it focuses on the events most useful for high-fidelity detection at fleet scale, but many organizations want richer, more granular signals for deeper hunting, compliance, or auditing purposes. Custom data collection lets you go beyond what Defender already captures without ever leaving the Defender portal. Easily build custom collection rules based on your organization’s specific needs using natural language; no PhD required! It includes several highly requested data types, including AMSI for hunting over script content, and Kerberos for hunting auth-based and network attacks.&lt;/P&gt;
&lt;P&gt;This truly integrated custom data offering is possible thanks to Microsoft’s platform approach, as the additional telemetry can be collected and analyzed via Defender and stored via Microsoft Sentinel. It puts you in complete control of any customized, add-on data, including exactly which data types are collected and how long they are stored. No other security solution has fully integrated and customizable telemetry collection and analysis.&lt;/P&gt;
&lt;H4&gt;Example custom telemetry scenario: detecting C2 communications&lt;/H4&gt;
&lt;P&gt;Many organizations have a set of assets that require special attention, like internet-facing servers, domain controllers, and other high-value endpoints where deeper telemetry can make the difference between catching an intrusion early and discovering it after the damage is done.&lt;/P&gt;
&lt;P&gt;Imagine your organization has received threat intelligence on attacks using stealthy C2 frameworks: HTTPS beacons with jittered intervals, DNS-based data exchange, and persistence via scheduled tasks and registry modifications. You want richer visibility into those internet-facing servers and high-value endpoints so you can hunt for these patterns proactively, instead of reconstructing them after the fact.&lt;/P&gt;
&lt;P&gt;Dynamic tags scope these high-value devices into a targeted group, and custom data collection captures the extra process, network, and registry events from them, giving analysts the telemetry they need to hunt for beaconing, suspicious DNS patterns, and persistence before attackers establish a foothold.&lt;/P&gt;
&lt;P&gt;To detect C2 communications using dynamic tagging, follow these steps:&lt;/P&gt;
&lt;H4&gt;&lt;U&gt;&lt;STRONG&gt;Step 1: Tag your devices&lt;/STRONG&gt;&lt;/U&gt;&lt;/H4&gt;
&lt;P&gt;Custom Data Collection rules are scoped to&amp;nbsp;&lt;STRONG&gt;dynamic tags; &lt;/STRONG&gt;once set,&lt;STRONG&gt; &lt;/STRONG&gt;those tags are automatically applied and removed based on conditions you define. Configure them in&amp;nbsp;&lt;STRONG&gt;Settings &amp;gt; Microsoft Defender XDR &amp;gt; Asset Rule Management&lt;/STRONG&gt;.&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Tag&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Rule name&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Conditions&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Tag to apply&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Internet-facing servers&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;InternetFacing-Servers&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Internet facing = true AND OS platform equals&amp;nbsp;Windows Server 2022&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;C2-Watchlist&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Devices under active investigation&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;HighSev-Investigation&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Manual tag equals&amp;nbsp;UnderInvestigation&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;HighSev-Verbose&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;&lt;img /&gt;&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;Bringing manual tags into the dynamic model&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;Custom data collection is built around&amp;nbsp;&lt;STRONG&gt;dynamic tags&lt;/STRONG&gt;&amp;nbsp;by design: one leading, unified tagging experience that's more flexible and customizable. Dynamic tags can be driven by device properties, group membership, OS,&amp;nbsp;&lt;EM&gt;or&lt;/EM&gt;&amp;nbsp;by existing manual tags, so anything your team already tags manually flows naturally into custom data collection through a simple Asset Rule Management rule, exactly as Tag 2 above does.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In this example, analysts manually tag a device&amp;nbsp;UnderInvestigation&amp;nbsp;during incident response. The dynamic rule picks up that manual tag and applies&amp;nbsp;HighSev-Verbose, which custom data collection rules can target. The analyst doesn't need to know about dynamic tags they tag the device the way they always have, and custom data collection activates &lt;STRONG&gt;automatically&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;H4&gt;&lt;U&gt;&lt;STRONG&gt;Step 2: Build your collection rules&lt;/STRONG&gt;&lt;/U&gt;&lt;/H4&gt;
&lt;P&gt;Navigate to&amp;nbsp;&lt;STRONG&gt;Settings &amp;gt; Endpoints &amp;gt; Rules &amp;gt; Custom Data Collection&lt;/STRONG&gt;. Select your Microsoft Sentinel workspace in the top-right corner.&lt;/P&gt;
&lt;P&gt;Before creating rules, confirm you meet every prerequisite in the&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-endpoint/create-custom-data-collection-rules" target="_blank" rel="noopener"&gt;custom data collection documentation&lt;/A&gt;&amp;nbsp;, in particular, your tenant must be onboarded to the&amp;nbsp;&lt;STRONG&gt;Unified Security Operations Platform (USOP)&lt;/STRONG&gt;.&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;Rule 1: Outbound network connections from high-risk processes&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;Capture connections from processes commonly abused by C2 frameworks living-off-the-land binaries and scripting engines.&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Setting&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Value&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Rule name&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;C2-OutboundConnections&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Table&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;DeviceCustomNetworkEvents&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Action&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Connection Success&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Condition&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;InitiatingProcessFileName Equals: powershell.exe,&amp;nbsp;rundll32.exe,&amp;nbsp;regsvr32.exe,&amp;nbsp;mshta.exe,&amp;nbsp;certutil.exe,&amp;nbsp;msiexec.exe&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Scope&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Devices tagged&amp;nbsp;C2-Watchlist&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;H5&gt;&lt;STRONG&gt;Rule 2: DNS query activity&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;Many C2 frameworks use DNS for beaconing or data exchange. Default telemetry captures limited DNS data. This rule collects all DNS queries from monitored devices.&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Setting&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Value&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Rule name&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;C2-DNSActivity&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Table&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;DeviceCustomNetworkEvents&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Action&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Connection Success&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Condition&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;RemotePort equals&amp;nbsp;53&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Scope&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Devices tagged&amp;nbsp;C2-Watchlist&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;H5&gt;&lt;STRONG&gt;Rule 3: Persistence mechanisms&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;C2 implants establish persistence via scheduled tasks, registry run keys, or services. Capture process creation events for common persistence tools.&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Setting&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Value&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Rule name&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;C2-Persistence&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Table&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;DeviceCustomProcessEvents&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Action&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Process Created&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Condition&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;FileName in (schtasks.exe,&amp;nbsp;reg.exe,&amp;nbsp;sc.exe,&amp;nbsp;at.exe)&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Scope&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Devices tagged&amp;nbsp;C2-Watchlist&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;H5&gt;&lt;STRONG&gt;Rule 4: Full process and script telemetry during investigations&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;When a device gets the&amp;nbsp;HighSev-Verbose&amp;nbsp;tag, collect everything.&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Setting&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Value&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Rule name&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;HighSev-AllProcesses&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Table&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;DeviceCustomProcessEvents&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Action&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Process Created&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Condition&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Broad (all process creation events)&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Scope&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Devices tagged&amp;nbsp;HighSev-Verbose&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Setting&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Value&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Rule name&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;HighSev-ScriptCapture&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Table&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;DeviceCustomScriptEvents&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Action&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Script execution&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Condition&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Broad (all script events) – add a condition which is always true such as&lt;/P&gt;
&lt;P&gt;FileName not equals “”&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Scope&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Devices tagged&amp;nbsp;HighSev-Verbose&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;Collection profiles summary&lt;/STRONG&gt;&lt;/H5&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Tag&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Rules active&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;What gets collected&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Use case&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;C2-Watch&amp;nbsp;list&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;OutboundConnections, DNSActivity, Persistence&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Network connections from, DNS queries, persistence tool usage, DLL sideloading&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Persistent C2 monitoring&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;HighSev-Verbose&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;AllProcesses, ScriptCapture&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Every process creation, all script execution&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Full-depth incident response&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;Important:&lt;/STRONG&gt;&amp;nbsp;when you remove the&amp;nbsp;HighSev-Verbose&amp;nbsp;tag after closing an incident, collection automatically drops back to baseline, no manual rule cleanup needed. This is what makes verbose collection safe to leave configured: it's only active while the tag is.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H4&gt;&lt;U&gt;&lt;STRONG&gt;Step 3: Hunt&lt;/STRONG&gt;&lt;/U&gt;&lt;/H4&gt;
&lt;P&gt;Rules deploy within 20 minutes to an hour. Query the data in AH directly.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Detect beaconing patterns processes making regular-interval outbound connections:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;STRONG&gt;Find DNS queries to high-entropy domains (potential DGA):&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Spot persistence being established:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Leverage the telemetry from your new collection rule into a Custom Detection so high-value findings raise alerts automatically, instead of waiting for the next manual hunt.&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Custom data collection effectively extends your endpoint protection into a targeted, general-purpose log collector, one that's now ready to serve advanced hunting, custom detections,&amp;nbsp;&lt;EM&gt;and&lt;/EM&gt; auditing or regulatory use cases, while default fleet-wide telemetry stays tuned for performance and signal-to-noise. By combining dynamic tagging with purpose-built collection rules, your highest-risk devices are always streaming the signals that matter most, ready for detection and investigation before and during an incident.&lt;/P&gt;
&lt;H4&gt;Learn more&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;To learn more about endpoint protection with Microsoft Defender, check out our&amp;nbsp;&lt;A href="https://www.microsoft.com/security/business/endpoint-security/microsoft-defender-endpoint" target="_blank" rel="noopener"&gt;website&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;To learn more about Microsoft Security solutions, visit our &lt;A href="https://www.microsoft.com/en-us/security/business" target="_blank" rel="noopener"&gt;website.&lt;/A&gt; Bookmark the &lt;A href="https://www.microsoft.com/security/blog/" target="_blank" rel="noopener"&gt;Security blog&lt;/A&gt; to keep up with our expert coverage on security matters. Follow us on LinkedIn (&lt;A href="https://www.linkedin.com/showcase/microsoft-security/" target="_blank" rel="noopener"&gt;Microsoft Security&lt;/A&gt;) and X (&lt;A href="https://twitter.com/@MSFTSecurity" target="_blank" rel="noopener"&gt;@MSFTSecurity&lt;/A&gt;) for the latest news and updates on cybersecurity.&lt;/LI&gt;
&lt;LI&gt;To learn more about custom data collection and how to get started, see our &lt;A href="https://learn.microsoft.com/en-us/defender-endpoint/create-custom-data-collection-rules" target="_blank" rel="noopener"&gt;documentation&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 09 Jun 2026 16:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/elevate-your-telemetry-using-custom-data-collection-in-microsoft/ba-p/4512530</guid>
      <dc:creator>Theo_Cohen</dc:creator>
      <dc:date>2026-06-09T16:00:00Z</dc:date>
    </item>
    <item>
      <title>Ways to fetch quarantine files</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/ways-to-fetch-quarantine-files/m-p/4526637#M6884</link>
      <description>&lt;P&gt;We are working with quarantine files and have a few questions:&lt;/P&gt;&lt;P&gt;1. Is there a public API available to retrieve quarantined files from Microsoft Defender for Endpoint?&lt;/P&gt;&lt;P&gt;2. Is there a documented method to map an alert or a file SHA-1/SHA-256 hash to the corresponding object in the Defender quarantine store?&lt;/P&gt;&lt;P&gt;3. Is there a way to retrieve quarantined files other than using a PowerShell script through the Live Response API?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2026 05:36:57 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/ways-to-fetch-quarantine-files/m-p/4526637#M6884</guid>
      <dc:creator>Dhwani_Shah</dc:creator>
      <dc:date>2026-06-09T05:36:57Z</dc:date>
    </item>
    <item>
      <title>Microsoft Defender now monitors RPC activity</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/microsoft-defender-now-monitors-rpc-activity/ba-p/4523368</link>
      <description>&lt;P&gt;Remote procedure call (RPC) is a protocol commonly abused by attackers that allows functions implemented in a separate process, and potentially on a remote machine, to be called as if they were local. Many core Windows and Active Directory capabilities are built on or make use of RPC, which makes it an attractive target. To help protect against remote RPC-based attacks, Microsoft Defender now monitors remote RPC calls, disrupts malicious activity that leverages them, and surfaces relevant telemetry in advanced hunting.&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;RPC basics&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;While &lt;A href="https://learn.microsoft.com/en-us/windows/win32/rpc/rpc-start-page" target="_blank" rel="noopener"&gt;RPC is a rich and complicated protocol&lt;/A&gt;, the main components that are relevant for security monitoring purposes are:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;U&gt;Interface&lt;/U&gt;: A logical grouping of functionality exposed by an RPC server. Interfaces are identified by UUID. Example interfaces include Task Scheduler, Remote Registry, and the Service Control Manager, each exposing functionality related to a different Windows OS component.&lt;/LI&gt;
&lt;LI&gt;&lt;U&gt;OpNum&lt;/U&gt;: Stands for Operation Number, an ordinal that denotes a specific function exposed by an RPC interface. Examples include RCreateServiceW (OpNum 12, Service Control Manager interface) and BaseRegQueryValue (OpNum 17, Remote Registry interface).&lt;/LI&gt;
&lt;/OL&gt;
&lt;H5&gt;&lt;STRONG&gt;Many remote attack techniques and tactics are based on RPC, for example:&lt;/STRONG&gt;&lt;/H5&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;U&gt;Lateral movement&lt;/U&gt;: often abuses RPC functionality for remotely creating tasks, services or invoking WMI.&lt;/LI&gt;
&lt;LI&gt;&lt;U&gt;Credential theft&lt;/U&gt;: DCsync attacks, which abuse privileged compromised accounts to remotely extract credential material from Active Directory, are based on RPC functionality for directory replication. SecretsDump and similar attacks, which remotely extract SAM or LSA secrets, are based on querying a device’s registry remotely, using RPC.&lt;/LI&gt;
&lt;LI&gt;&lt;U&gt;Privilege escalation&lt;/U&gt;: Multiple authentication coercion attacks abuse benign RPC interfaces to coerce servers to authenticate an attacker.&lt;/LI&gt;
&lt;LI&gt;&lt;U&gt;Discovery&lt;/U&gt;: Tools such as SharpHound leverage RPC calls to enumerate users, sessions and shares.&lt;/LI&gt;
&lt;/OL&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;For a more comprehensive mapping of RPC interfaces to attack techniques, see&amp;nbsp;&lt;A href="https://github.com/jonny-jhnson/MSRPC-to-ATTACK" target="_blank" rel="noopener"&gt;work&lt;/A&gt; by Jonathan Johnson.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H5&gt;&lt;STRONG&gt;RPC auditing in Defender&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;Since RPC is so heavily used on Windows systems and in Active Directory domains, monitoring remote RPC traffic using network monitors is often expensive and infeasible. Additionally, if the underlying transport protocol is encrypted (such as SMB3), it might be impossible to observe RPC traffic.&lt;/P&gt;
&lt;P&gt;To enable efficient auditing of remote RPC activity regardless of transport-layer protection, Defender research and engineering expanded the existing RPC integration with the Windows Filtering Platform (WFP) to support OpNum-level granularity. This makes it possible to identify and audit the specific RPC function being invoked, rather than only the RPC interface.&lt;/P&gt;
&lt;P&gt;This capability is designed to help detect remote RPC-based attack techniques, where an attacker interacts with RPC interfaces exposed by a target device. For that reason, Defender focuses this monitoring on inbound remote RPC calls observed on the RPC server host. The telemetry is collected using audit-only WFP filters, which do not interfere with normal traffic, while still providing visibility into suspicious remote activity targeting the device. This approach does not require visibility into the source device.&lt;/P&gt;
&lt;P&gt;Local RPC calls, such as inter-process communication on the same device over local transport, and outbound RPC client calls are outside the scope of this monitoring mechanism.&lt;/P&gt;
&lt;P&gt;Using this capability, Defender monitors selected RPC calls, leverages the resulting telemetry to detect malicious activity, and exposes monitored calls in advanced hunting. Defender dynamically monitors selected remote operations from interfaces including, but not limited to: Remote Registry, Service Control Manager, Task Scheduler, and Windows Management Instrumentation (WMI). RPC monitoring for workstations is generally available, while server monitoring is currently in gradual rollout.&lt;/P&gt;
&lt;P&gt;RPC-based detections and disruption triggers are already available in Defender and include detections such as:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Ongoing hands-on-keyboard attack via Impacket toolkit&lt;/LI&gt;
&lt;LI&gt;Suspicious service creation initiated remotely&lt;/LI&gt;
&lt;LI&gt;Indication of local security authority secrets theft&lt;/LI&gt;
&lt;LI&gt;Unusual RPC user and session discovery&lt;/LI&gt;
&lt;LI&gt;Authentication coercion attack&lt;/LI&gt;
&lt;/OL&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;H5&gt;&lt;STRONG&gt;Example Advanced Hunting queries&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;1. Remote registry key save events, abused for remote credential dumping.&lt;/P&gt;
&lt;LI-CODE lang=""&gt;let remoteRegistryInterface = '338cd001-2244-31f1-aaaa-900038001003'; 
let registrySaveOpnums = dynamic([20, 31]); // BaseRegSaveKey, BaseRegSaveKeyEx 
DeviceEvents 
| where ActionType == 'InboundRemoteRpcCall' 
| extend AdditionalFields = parse_json(AdditionalFields) 
| extend RpcInterface = tostring(AdditionalFields.RpcInterfaceUuid), OpNum = toint(AdditionalFields.RpcOpNum) 
| where RpcInterface == remoteRegistryInterface and OpNum in(registrySaveOpnums) &lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. Remote Service Creation events, could indicate lateral movement:&lt;/P&gt;
&lt;LI-CODE lang=""&gt;let remoteServicesInterface = '367abb81-9844-35f1-ad32-98f038001003'; 
let serviceCreationOpnums = dynamic([12, 24, 44, 45, 60]); // RCreateServiceW, RCreateServiceA, RCreateServiceWOW64A, RCreateServiceWOW64W, RCreateWowService 
DeviceEvents 
| where ActionType == 'InboundRemoteRpcCall' 
| extend AdditionalFields = parse_json(AdditionalFields) 
| extend RpcInterface = tostring(AdditionalFields.RpcInterfaceUuid), OpNum = toint(AdditionalFields.RpcOpNum) 
| where RpcInterface == remoteServicesInterface and OpNum in(serviceCreationOpnums) &lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3. Session discovery events, could indicate account discovery:&lt;/P&gt;
&lt;LI-CODE lang=""&gt;let srvsvcInterface = '4b324fc8-1670-01d3-1278-5a47bf6ee188'; 
let netrSessionEnumOpnum = 12; 
DeviceEvents 
| where ActionType == 'InboundRemoteRpcCall' 
| extend AdditionalFields = parse_json(AdditionalFields) 
| extend RpcInterface = tostring(AdditionalFields.RpcInterfaceUuid), OpNum = toint(AdditionalFields.RpcOpNum) 
| where RpcInterface == srvsvcInterface and OpNum == netrSessionEnumOpnum 
| summarize dcount(DeviceId) by AccountName, AccountDomain, AccountSid &lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check out the advanced hunting tab to see monitored RPC activity in your environment and stay tuned for more updates from Defender.&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;Learn more&lt;/STRONG&gt;&lt;/H5&gt;
&lt;UL&gt;
&lt;LI&gt;To learn more about endpoint protection with Microsoft Defender, check out our&amp;nbsp;&lt;A href="https://www.microsoft.com/security/business/endpoint-security/microsoft-defender-endpoint" target="_blank" rel="noopener"&gt;website&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;To learn more about Microsoft Security solutions, visit our &lt;A href="https://www.microsoft.com/en-us/security/business" target="_blank" rel="noopener"&gt;website.&lt;/A&gt; Bookmark the &lt;A href="https://www.microsoft.com/security/blog/" target="_blank" rel="noopener"&gt;Security blog&lt;/A&gt; to keep up with our expert coverage on security matters. Follow us on LinkedIn (&lt;A href="https://www.linkedin.com/showcase/microsoft-security/" target="_blank" rel="noopener"&gt;Microsoft Security&lt;/A&gt;) and X (&lt;A href="https://twitter.com/@MSFTSecurity" target="_blank" rel="noopener"&gt;@MSFTSecurity&lt;/A&gt;) for the latest news and updates on cybersecurity.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 09 Jun 2026 16:55:28 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/microsoft-defender-now-monitors-rpc-activity/ba-p/4523368</guid>
      <dc:creator>EdanZwick</dc:creator>
      <dc:date>2026-06-09T16:55:28Z</dc:date>
    </item>
    <item>
      <title>Understanding AI workloads on Linux</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/understanding-ai-workloads-on-linux/m-p/4524856#M6883</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;I’m a PM working on security for Linux environments and trying to better understand how AI workloads are actually showing up in production today.&lt;/P&gt;
&lt;P&gt;Would appreciate hearing from folks here:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Are you running any AI workloads on Linux today? Or actively exploring?&lt;/LI&gt;
&lt;LI&gt;What does your deployment/setup look like — e.g., model training/inference, agents, MCP servers, data pipelines, etc.?&lt;/LI&gt;
&lt;LI&gt;How are you thinking about securing this stack, if at all?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If you’re open to a quick &lt;STRONG&gt;30-min chat&lt;/STRONG&gt;, I’d love to learn more from your experience as well.&lt;/P&gt;
&lt;P&gt;Thanks in advance — this will directly help shape where we invest next.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2026 15:01:12 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/understanding-ai-workloads-on-linux/m-p/4524856#M6883</guid>
      <dc:creator>tejaskashyap</dc:creator>
      <dc:date>2026-06-02T15:01:12Z</dc:date>
    </item>
    <item>
      <title>How Microsoft Defender used predictive shielding to proactively disrupt a ransomware attack</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/how-microsoft-defender-used-predictive-shielding-to-proactively/ba-p/4519498</link>
      <description>&lt;P&gt;Modern ransomware attacks are increasingly designed to blend in with normal IT operations, using trusted administrative tools to quietly weaken defenses and distribute malicious payloads at scale.&lt;/P&gt;
&lt;P&gt;In a recent real‑world incident, a human‑operated ransomware actor attempted to do exactly that by abusing &lt;STRONG&gt;Group Policy Objects (GPOs) to target hundreds of devices, but Microsoft Defender detected the attack and proactively hardened those devices before GPOs were deployed.&lt;/STRONG&gt;&lt;/P&gt;
&lt;H4&gt;The attacker’s plan&lt;/H4&gt;
&lt;P&gt;The target organization, a large educational institution with more than a couple of thousand devices onboarded to Microsoft Defender, had already experienced a compromise of a domain admin account from an unmanaged device before the ransomware deployment attempt began.&lt;/P&gt;
&lt;P&gt;Because GPOs are a trusted mechanism for pushing configuration changes across devices, they present an attractive path for attackers looking to disable security tools or deploy ransomware broadly without needing to access each machine individually. This attacker’s plan involved weaponizing GPOs to:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Push tampering configurations that could disable Defender protections across the environment&lt;/LI&gt;
&lt;LI&gt;Distribute and execute ransomware via scheduled tasks&lt;/LI&gt;
&lt;LI&gt;Leverage built‑in enterprise infrastructure to scale the attack&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This approach allowed the attacker to attempt ransomware deployment through standard administrative channels, minimizing the need for direct interaction with individual devices and increasing the potential for widespread impact.&lt;/P&gt;
&lt;H4&gt;How Defender thwarted the attack&lt;/H4&gt;
&lt;P&gt;First, Defender quickly detected the attack and contained the domain admin account that the attacker had compromised. Then, since the attacker had created a malicious GPO that disabled key Defender protections, a Defender tampering alert was triggered. In response, predictive shielding activated GPO hardening, temporarily pausing the propagation of new GPO policies across all MDE onboarded devices reachable from the attacker’s standpoint and achieved protection of ~85% of devices against the tampering policy before ransomware was deployed.&lt;/P&gt;
&lt;P&gt;Ten minutes later, the attacker attempted to distribute ransomware, but because GPO hardening had already been applied, GPO propagation was already disabled on the targeted devices and the attacker was unsuccessful. Defender recognized that GPO tampering is a precursor to ransomware distribution and acted preemptively. It didn’t wait for ransomware to appear; it acted on what the attacker was&amp;nbsp;&lt;EM&gt;about&lt;/EM&gt; to do, preventing downstream impact such as recovery costs and operational downtime.&lt;/P&gt;
&lt;H4&gt;The results&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;Zero machines were encrypted via the GPO path.&lt;/LI&gt;
&lt;LI&gt;Roughly 97% of devices the attacker attempted to encrypt were fully protected by Defender. A limited number of devices&amp;nbsp;experienced encryption during concurrent ransomware activity over SMB; however, attack disruption successfully contained the incident and stopped further impact.&lt;/LI&gt;
&lt;LI&gt;700 devices applied the predictive shielding GPO hardening policy, reflecting the attacker’s broad targeting scope, and blocking the propagation of the malicious policy set by the attacker within approximately 3 hours.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Attackers are getting more sophisticated, finding ways to evade detection by abusing legitimate IT tools that organizations rely on and can’t simply turn off. Security teams can’t restrict these mechanisms without impacting daily operations. By detecting ransomware staging and predicting the attacker’s next move, Defender can apply targeted restrictions just in time, shifting from reactive response to proactive prevention, stopping only what matters when it matters while maintaining full business productivity. With average ransom demands now ranging from $2–5M, the downstream recovery and remediation savings from preventing these attacks can be massive.&lt;/P&gt;
&lt;H4&gt;Learn more&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;To learn more about this specific attack, check out the full case study: &lt;A href="https://www.microsoft.com/en-us/security/blog/2026/03/23/case-study-predictive-shielding-defender-stopped-gpo-based-ransomware-before-started/" target="_blank" rel="noopener"&gt;Case study: How predictive shielding in Defender stopped GPO-based ransomware before it started&lt;/A&gt; &lt;A href="https://www.microsoft.com/en-us/security/blog/2026/03/23/case-study-predictive-shielding-defender-stopped-gpo-based-ransomware-before-started/" target="_blank" rel="noopener"&gt;[microsoft.com]&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;To learn more about endpoint protection with Microsoft Defender, check out our&amp;nbsp;&lt;A href="https://www.microsoft.com/security/business/endpoint-security/microsoft-defender-endpoint" target="_blank" rel="noopener"&gt;website&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;To learn more about Microsoft Security solutions, visit our &lt;A href="https://www.microsoft.com/en-us/security/business" target="_blank" rel="noopener"&gt;website.&lt;/A&gt; Bookmark the &lt;A href="https://www.microsoft.com/security/blog/" target="_blank" rel="noopener"&gt;Security blog&lt;/A&gt; to keep up with our expert coverage on security matters. Follow us on LinkedIn (&lt;A href="https://www.linkedin.com/showcase/microsoft-security/" target="_blank" rel="noopener"&gt;Microsoft Security&lt;/A&gt;) and X (&lt;A href="https://twitter.com/@MSFTSecurity" target="_blank" rel="noopener"&gt;@MSFTSecurity&lt;/A&gt;) for the latest news and updates on cybersecurity.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 01 Jun 2026 17:16:47 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/how-microsoft-defender-used-predictive-shielding-to-proactively/ba-p/4519498</guid>
      <dc:creator>AvivSharon</dc:creator>
      <dc:date>2026-06-01T17:16:47Z</dc:date>
    </item>
    <item>
      <title>Larac2shell: Turning MDE Live Response into a near real-time shell We are the EDR!</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/larac2shell-turning-mde-live-response-into-a-near-real-time/m-p/4517733#M6878</link>
      <description>&lt;P&gt;&lt;A class="lia-external-url" href="https://github.com/akefallonitis/larac2shell" target="_blank"&gt;https://github.com/akefallonitis/larac2shell&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Turning MDE live response into a near real time interactive shell beta version out&lt;/P&gt;&lt;P&gt;Features:&lt;/P&gt;&lt;P&gt;- Internal (Thanks to&amp;nbsp;&lt;A href="https://www.linkedin.com/in/fabianbader/" target="_blank"&gt;Fabian Bader&lt;/A&gt;&amp;nbsp;-&amp;nbsp;&lt;A href="https://www.linkedin.com/in/nathanmcnulty/" target="_blank"&gt;Nathan McNulty&lt;/A&gt;&amp;nbsp;and xdrinternals research ) vs External api authentication&lt;BR /&gt;- Arbitrary command execution via pre-uploaded base64 wrapper script&lt;BR /&gt;- Cross-OS support&lt;/P&gt;&lt;P&gt;PS Two MSRC bugs reported for direct command execution bypass waiting for Microsoft Response in order to publish them&lt;/P&gt;&lt;P&gt;Coming SOON TM&lt;/P&gt;&lt;P&gt;Full LaraC2 Post Exploitation OST framework over MDE as C2/C3 Channel - We are the EDR / No external Infra / Onboarding to your controlled tenant silencing MDE&lt;/P&gt;&lt;P&gt;Happy testing 🥳 🎉&lt;/P&gt;</description>
      <pubDate>Fri, 08 May 2026 08:25:12 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/larac2shell-turning-mde-live-response-into-a-near-real-time/m-p/4517733#M6878</guid>
      <dc:creator>alkefallonitis</dc:creator>
      <dc:date>2026-05-08T08:25:12Z</dc:date>
    </item>
  </channel>
</rss>

