La nuova quarantena di Defender può anche bloccare la risposta
Microsoft sta inserendo il contenimento in Defender for Endpoint, e quella stessa automazione può diventare un punto di disruption se viene lasciata troppo permissiva. La promessa è un rapido isolamento di un dispositivo sospetto; il rischio è che la logica di risposta stessa possa essere abusata per escludere gli amministratori dai loro account e rallentare la gestione degli incidenti.
Microsoft previews automatic device isolation in Defender for Endpoint
The new capability will be added to the automatic attack disruption tool, however, new research warns that the tool has to be tuned to avoid it becoming an attack vector.
Microsoft Defender can now automatically isolate hacked endpoints
Microsoft is testing a new Defender for Endpoint capability that will automatically isolate compromised endpoints to thwart attackers' attempts to move laterally across the network.