News: 1677220214

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Microsoft grows automated assault disruption to cover BEC, ransomware campaigns

(2023/02/24)


At last year's Ignite show, Microsoft talked up a capability in its 365 Defender that automatically detects and disrupts a cyberattack while still in progress, hopefully stopping or reducing any resulting damage. Now it's extending that to include additional criminal areas.

The [1]automatic attack disruption functionality aimed at corporate security operation centers (SOCs) uses millions of data points and signals to identify active malware campaigns – including ransomware – and take steps to automatically isolate the device under attack from the network and to suspended accounts compromised by the attackers.

The software and cloud services giant has now expanded the public preview of the automatic attack disruption capability to cover business email compromise (BEC) and human-operated ransomware (HumOR) attacks.

[2]

"Business email compromise and human-operated ransomware attacks are two common attack scenarios that are now supported by Microsoft 365 Defender's automatic attack disruption capabilities to reduce their impact on an organization," Eval Haik, senior product manager at Microsoft, wrote in a [3]post .

[4]

[5]

Miscreants running BEC campaigns target organizations to attack and uses social engineering techniques to trick victims within the company to inadvertently download malware, request payment from vendors, or transferring funds to an account controlled by the attacker.

An FBI report last year said that between 2016 and 2021, there were [6]241,206 BEC incidents worldwide that cost organizations more than $43.3 billion.

[7]Microsoft to enterprises: Patch your Exchange servers

[8]Microsoft delivers 75-count box of patches for Valentine's Day

[9]Here's a list of proxy IPs to help block KillNet's DDoS bots

[10]Attackers abuse Microsoft's 'verified publisher' status to steal data

In [11]HumOR attacks – as opposed to automated ransomware campaigns – criminals get into a company's on-premises systems or cloud infrastructure, elevate privileges, move laterally, and deploy ransomware on a massive scale. The attacks target an entire organization rather than individual devices and involve credential theft and deploying ransomware.

Time is short

The rollout of automatic attack disruption in Microsoft 365 Defender is a nod not only to the increasing numbers and sophistication of cyberattacks, but also their sheer velocity and growing expertise. Attacks are often well underway before security teams can detect them, much less slow them down.

Microsoft has found that by once a miscreant deploys ransomware in a network, a SOC analyst has less than 20 minutes to mitigate the attack. It can take less than two hours from the time a worker clicks on a phishing link to when an attacker gains full access to the user's inbox and is moving laterally through the network.

[12]

"This narrow time frame, coupled with the high technical skills and time required to perform the analysis, makes manually responding near impossible," Haik wrote.

Microsoft Defender 365 uses AI-based detection capabilities to correlate a range of extended detection and response (XDR) signals across endpoints, identities, email, and software-as-a-service (SaaS) applications to identify cyberattacks. There's also analysis identifying malicious activities, from credential theft and lateral movement to product tampering.

All this triggers the automatic attack disruption capability to disable the compromised user accounts in Active Directory and Azure AD and contain devices to ensure they can't communicate with a compromised machine.

[13]

"Automation is critical to scaling SOC teams' capabilities across today's complex, distributed, and diverse ecosystems," Microsoft wrote in a [14]post in October 2022 when the feature was introduced at Ignite.

System admins can see what's happening through an "Attack Disruption" tag next to affected incidents in the Incident queue and, in the Incident page, an "Attack Disruption" tab, a yellow banner at the top of a page showing the automatic action that was taken, and an incident graph showing an asset's status, such as an account being disabled or a device contained.

Security teams also can customize how automatic attack disruption is configured and change an action via the Microsoft 365 Defender Portal. ®

Get our [15]Tech Resources



[1] https://www.theregister.com/2022/10/12/microsoft_ignite_security/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y-iY0MkIakl6IIy3-BWQvQAAAAo&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://techcommunity.microsoft.com/t5/microsoft-365-defender-blog/automatic-disruption-of-ransomware-and-bec-attacks-with/ba-p/3738294

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y-iY0MkIakl6IIy3-BWQvQAAAAo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y-iY0MkIakl6IIy3-BWQvQAAAAo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.ic3.gov/Media/Y2022/PSA220504

[7] https://www.theregister.com/2023/01/28/microsoft_patch_exchange_servers/

[8] https://www.theregister.com/2023/02/14/microsoft_adobe_patch_tuesday/

[9] https://www.theregister.com/2023/02/06/killnet_proxy_ip_list/

[10] https://www.theregister.com/2023/02/01/microsoft_oauth_attack_proofpoint/

[11] https://learn.microsoft.com/en-us/security/compass/human-operated-ransomware

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y-iY0MkIakl6IIy3-BWQvQAAAAo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y-iY0MkIakl6IIy3-BWQvQAAAAo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[14] https://techcommunity.microsoft.com/t5/microsoft-365-defender-blog/what-s-new-in-xdr-at-microsoft-ignite/ba-p/3648872

[15] https://whitepapers.theregister.com/



And when Defender is the attacker?

Richard 12

We still haven't recovered from when Microsoft deleted all our shortcuts.

I mean, I know SAP is a pain, but it's business critical so permanently removing it from everyone's desktop and Start menu was most unhelpful.

Re: And when Defender is the attacker?

Lil Endian

SAP is A Pain - Ah! It's that one of those recursive acronyms, like WINE! I never knew :)

A nod ?

Pascal Monett

How about a nod to the fact that the pervasiveness of Borkzilla's network management is a free ride for most hackers, who only have to understand one platform in order to potentially get their claws into 90+% of businesses the world over ?

Re: A nod ?

Anonymous Coward

The pervasiveness isn't the problem, the abysmal quality of what Microsoft laughingly refers to as "security" is.

If they would spend 1/10h of what they blow on bribes dinners and golf courses on improving security there would be far less of a problem, but them now considering it acceptable to use their customers as beta testers suggests that things are rather moving the other way.

After all, once entangled, victims customers have little choice but to continue suffering..

A general leading the State Department resembles a dragon commanding ducks.
-- New York Times, Jan. 20, 1981