Defender XDR isolates devices automatically in 128 seconds
Microsoft is extending automatic attack disruption in Defender XDR with a new response action. When the system identifies a compromised workstation as an active attack foothold with high confidence, it can isolate the device from the network automatically. In an incident documented by Microsoft at QNET, only 128 seconds passed between the first detection and … Read more
