Microsoft Defender Threat Intelligence
13 TopicsAdd Privacy Scrub Service to Microsoft Defender?
Microsoft Defender protects accounts against phishing and malware, but attackers increasingly exploit nuisance data broker sites that publish personal information (names, emails, addresses). These sites are scraped to personalize phishing campaigns, making them harder to detect. I propose a premium Defender add‑on that automatically files opt‑out requests with major data brokers (similar to DeleteMe).40Views0likes1CommentQuestion behavior same malware
Two malware with the same detection name but on different PCs and files, do they behave differently or the same? Example: Two detections of Trojan:Win32/Wacatac.C!ml 1) It remains latent in standby mode, awaiting commands. 2) It modifies, deletes, or corrupts files.144Views0likes3CommentsQuestion malware detected Defender for Windows 10
Why did my Microsoft Defender detect a malicious file in AppData\Roaming\Secure\QtWebKit4.dll (Trojan:Win32/Wacatac.C!ml) during a full scan and the Kaspersky Free and Malwarebytes Free scans didn't detect it? Was it maliciously modifying, corrupting, or deleting various files on my PC before detection? I sent it to Virus Total, the hash: 935cd9070679168cfcea6aea40d68294ae5f44c551cee971e69dc32f0d7ce14b Inside the same folder as this DLL, there's another folder with a suspicious file, Caller.exe. I sent it to Virus Total, and only one detection from 72 antivirus programs was found, with the name TrojanPSW.Rhadamanthys. VT hash: d2251490ca5bd67e63ea52a65bbff8823f2012f417ad0bd073366c02aa0b3828124Views0likes2CommentsWebsite incorrectly flagged as security threat (Safe Links false-positive)
Hi, Our SaaS-website atleta.cc is currently incorrectly flagged as security threat by Microsoft Defender / Safe Links. This is causing trouble for clients and customers of clients in Outlook, Edge etc. Where can we report this false-positive, or request removal from the block list? Thank you! Greetings, Jarno Example:246Views0likes0CommentsUnable to Disable User Quarantine Mails after enabling security presets
Hi, We have recently enabled security preset policies with Standard protection in our tenant. Since then, our users are receiving quarantine mails from Microsoft. We use AdminOnlyAccessPolicy for quarantine in Anti-spam and Anti-phishing threat policies and in a couple of transport rules and yet users are receiving these quarantine mails. We did try creating a custom quarantine policy and assigning it to Anti-spam and Anti-phishing threat policies, hoping it would override the preset policies, but it didn't work. I know we can either turn off preset policies or block these using transport rules, but these are last resorts. Is there any way or policy to stop these mails keeping the security preset policies on? Thanks in Advance!!Solved883Views0likes1CommentNew Blog | 10 essential insights from the Microsoft Digital Defense Report 2023
By Quy Nguyen Published Jan 08 2024 09:19 AM In an era marked by escalating cyber threats, Microsoft sheds light on the global security landscape through the Microsoft Digital Defense Report 2023. Harnessing extensive security research and a unique vantage point, Microsoft not only comprehends the current state of cybersecurity but also utilizes a diverse range of security data to predict and identify indicators of cyber threats. Read the full blog post here: Microsoft Digital Defense Report 20231.1KViews0likes0Comments- 1KViews0likes2Comments
Blocking someone from trying to log in
I was involved in a romance scam. I have my computer set up that you need to approve login through my cell phone. Now, I have reason to believe that he is unsuccessfully trying to login to my computer from different isps all over the world. He tries several times a day almost every day. I have enabled all the security ways that I can. Is there any way I can block him without the hassle of changing my email everywhere?1.2KViews0likes1CommentNew blog post | Entra Identity Governance with Entra Verified ID
I’m excited to announce the integration of Entra Identity Governance Entitlement Management with a very cool technology we recently introduced, Microsoft Entra Verified ID! If you think about what you need to onboard new users including employees, contractors, partners, or other business guests, it often includes verifying identity information and credentials. This process can be tedious and time-consuming, requiring users to fill out redundant online forms or paperwork, ultimately delaying hiring timelines and ramp-up periods. Entra Identity Governance with Entra Verified ID – Higher Fidelity Access Rights + Faster Onboarding - Microsoft Community Hub653Views0likes0CommentsNew Blog Post | The New Microsoft Security Customer Connection Program (CCP)
Read the full blog post: The New Microsoft Security Customer Connection Program (CCP) - Microsoft Community Hub The security community is constantly growing, changing, and learning from each other in order to better position the world against cyber security threats. For years, Microsoft has driven a customer-obsessed development process by hosting two private communities for end-users of Microsoft security products: the Microsoft Cloud Security Private Community and the Microsoft 365 Defender Customer Connection Program. Under a strict confidentiality framework, our engineering teams get direct community feedback and insights for our roadmap plans, new user experience designs, private preview features, and more. Today, we are happy to announce that these two communities have now come together under one team – The Microsoft Security Customer Connection Program.2.2KViews1like0Comments