News: 1675197905

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Microsoft upgrades Defender to lock down Linux gear for its own good

(2023/01/31)


Organizations using Microsoft's Defender for Endpoint will now be able to isolate Linux devices from their networks to contain intrusions and whatnot.

The device isolation capability is in public preview and mirrors what the product already does for Windows systems.

"Some attack scenarios may require you to isolate a device from the network," Microsoft wrote in a [1]blog post . "This action can help prevent the attacker from controlling the compromised device and performing further activities such as data exfiltration and lateral movement. Just like in Windows devices, this device isolation feature."

[2]

Intruders won't be able to connect to the device or run operations like assuming unauthorized control of the system or stealing sensitive data, Microsoft claims.

[3]

[4]

According to the vendor, when the device is isolated, it is limited in the processes and web destinations that are allowed. That means if they're behind a full VPN tunnel, they won't be able to reach Microsoft's Defender for Endpoint cloud services.

Microsoft recommends that enterprises use a split-tunneling VPN for cloud-based traffic for both Defender for Endpoint and Defender Antivirus. Once the situation that caused the isolation is cleared up, organizations will be able to reconnect the device to the network.

[5]

Isolating the system is done via APIs. Users can get to the device page of the Linux systems through the Microsoft 365 Defender portal, where they will see an "Isolate Device" tab in the upper right among other response actions. Microsoft has outlined the APIs for both [6]isolating the device and [7]releasing it from lock down.

Linux devices that can use the Defender for Endpoint include Red Hat Enterprise Linux (RHEL), CentOS, Ubuntu, Desbian, SUSE Linux, Oracle Linux, Amazon Web Services (AWS) Linux, and Fedora.

[8]Microsoft Defender ASR rules strip icons, app shortcuts from Taskbar, Start Menu

[9]Microsoft and community release scripts to help mitigate Defender mess

[10]Microsoft closes another door to attackers by blocking Excel XLL files from the internet

[11]If your Start menu or apps are freezing up on Windows, Microsoft has a suggestion

The Linux device isolation is the latest recent security feature Microsoft has put into the cloud service. Earlier this month, the company expanded the tamper protection for Defender for Endpoint to include antivirus exclusions.

This is all part of a wider pattern of beefing up Defender with an eye on open source. At its Ignite show in October 2022, Microsoft announced it was integrating the Zeek open-source network monitoring platform as a component of Defender for Endpoint for deep packet inspection of network traffic.

Also at the event, Redmond spoke about the new capabilities aimed at allowing security operations teams to detect command-and-control (C2) attacks earlier, enabling them to limit the spread of the damage and removing malicious binaries.

[12]

The new functionality also comes just more than two weeks after updates to Defender for Endpoint [13]threw a scare into security pros – on Friday the 13 th – by inadvertently removing icons and application shortcuts from the desktop, Taskbar, and Start Menu in Windows 10 and 11 systems. Microsoft fixed the issue, but still left users with some files being permanently deleted. ®

Get our [14]Tech Resources



[1] https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/announcing-device-isolation-support-for-linux/ba-p/3676400

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y9mdkfSAx2agOegUjX8ZpgAAAMs&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y9mdkfSAx2agOegUjX8ZpgAAAMs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y9mdkfSAx2agOegUjX8ZpgAAAMs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y9mdkfSAx2agOegUjX8ZpgAAAMs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/isolate-machine?view=o365-worldwide

[7] https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/unisolate-machine?view=o365-worldwide

[8] https://www.theregister.com/2023/01/13/happy_friday_13th_microsoft_defender/

[9] https://www.theregister.com/2023/01/16/microsoft_and_community_release_scripts/

[10] https://www.theregister.com/2023/01/25/microsoft_excel_xll_closed/

[11] https://www.theregister.com/2023/01/26/microsoft_windows_clickstart/

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y9mdkfSAx2agOegUjX8ZpgAAAMs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[13] https://www.theregister.com/2023/01/16/microsoft_and_community_release_scripts/

[14] https://whitepapers.theregister.com/



intruders

captain veg

"Intruders won't be able to connect to the device or run operations like assuming unauthorized control of the system or stealing sensitive data, Microsoft claims."

Have they demonstrated that intruders could connect to Linux devices or run operations like that without the "benefit" of Defender? Or does this, in fact, leave Linux users in much the same position as before but with some Microsoft bloatware installed?

-A.

Re: intruders

yetanotheraoc

"they won't be able to reach Microsoft's Defender for Endpoint cloud services"

If I read that right, what MS are doing is isolating a Linux box *from Defender*. This would be useful, potentially, because if Defender is compromised you can keep that compromise from spreading to the Linux boxen. Of course, if Defender is compromised then the intruders could probably just re-enable the isolated devices... But cool, it's one more green checkmark on the packaging, marketing is happy.

Re: intruders

Anonymous Coward

Yes, I read it that way also, which confuses me.

Defender doing more to support Linux is good news in general, giving us more tools to do our jobs with.

Is this the same Defender

Neil Barnes

That cheerfully announces that the website you just (knowingly and with malice aforethought) logged into is trying to steal your login?

Er...

original_rwg

Install a Micros~1 product on my Linux machine? Why would I want to do that? (Rhetorical question)

DistroWatch

yetanotheraoc

Desbian - Trust Microsoft to know which distros need isolating.

I've said some stupid things and some wrong things, but not that. No one
involved in computers would ever say that a certain amount of memory is enough
for all time ... I keep bumping into that silly quotation attributed to me that
says 640 K of memory is enough. There's never a citation; the quotation just
floats like a rumor, repeated again and again.

-- Gates (19 January 1996), "Career Opportunities in Computing-and More".
Bloomberg Business News

Do you realize the pain the industry went through while the IBM PC was limited
to 640 K? The machine was going to be 512 K at one point, and we kept pushing
it up. I never said that statement - I said the opposite of that.

-- "Gates talks". U.S. News & World Report. August 20, 2001. Retrieved on
October 8, 2014.

I have to say that in 1981, making those decisions, I felt like I was providing
enough freedom for 10 years. That is, a move from 64k to 640k felt like
something that would last a great deal of time. Well, it didn´t - it took about
only 6 years before people started to see that as a real problem.

-- speech to the Computer Science Club at the University of Waterloo, 1989

-- https://en.wikiquote.org/wiki/Bill_Gates#Misattributed