128 Seconds to disruption: Microsoft Defender stops ransomware at QNET
Brief
In this article
- What is device isolation?
- Case study: QNET
- Attack chain overview
- MITRE ATT&CK techniques observed
- References
- Learn more
Microsoft Defender’s attack disruption now includes device isolation, a new response action that extends autonomous protection directly to compromised endpoints.
At QNET, an attacker initiated a multi-stage attack using a legitimate Windows tool on a compromised endpoint to retrieve a malicious remote payload–a classic living-off-the-land (LOL) technique that often evades traditional containment. By automatically enforcing the new device isolation action on the compromised endpoint, Defender attack disruption stopped the attack dead in its tracks.
