Prevent repeat attacks with threat-informed security posture recommendations
As organizations continue to face an ever-evolving threat landscape, it is essential to have an effective posture management strategy in place. To do this effectively, security analysts not only need to consider industry standards and vendor best practices, but also take recent attacks into consideration. Investigating incidents that affected the organization helps understanding how the adversary got in and what misconfigurations were leveraged during the attack. These learnings enable security analysts to identify which settings should be addressed to close those gaps and prevent the organization from being affected by the same attack again.
Microsoft 365 Defender now makes it easy for security operations (SOC) teams to identify and prioritize the right controls with the general availability of threat-informed security posture recommendations.
This embedded experience maps techniques that were used during an attack on your organization to the relevant available security controls in Microsoft Secure Score and presents posture recommendations to prevent similar attacks from being successful again. The new experience delivers:
- Microsoft 365 Defender maps techniques used during an attack to available Microsoft Secure Score controls
- Prioritized security posture recommendations are shown in the new “Exposures and mitigations” tab on the relevant incident, as well as the threat analytics page of the associated threat
- Prevent similar attacks in the future by addressing the root cause and apply the recommended controls
Prevent repeat attacks
When investigating an incident or a new threat campaign, security analysts investigate, contain, respond, and remediate an attack. However, it’s also critical to continuously evaluate and fine tune an organization’s security settings after an attack is remediated to prevent the same attack from reoccurring.
Bringing posture recommendations available via Microsoft Secure Score into the threat analytics and incident views, Microsoft 365 Defender now maps the techniques used by the attacker to the vulnerabilities or misconfigurations that led to the breach. This gives security analysts the information within the context of an incident and helps implement a prioritized and threat-driven security posture plan.
This new capability analyzes incidents in your environment and recommends specific Microsoft Secure Score controls that can block the techniques used in previous incidents, enabling you to prioritize posture recommendations based on relevant, repetitive techniques, and reduce the risks of similar attacks.
Start using the new threat-informed posture recommendations
When investigating emerging threats, Microsoft 365 Defender researches and analyzes the techniques used by threat actors and maps them to security posture in Microsoft 365 Defender. These actions and their status are available in the threat analytics report, allowing you to focus on improving your organization’s resilience in the context of a specific emerging threat.
Figure 1: Example of a threat-informed posture recommendations within Threat Analytics
Understand your resilience against threats – In the Microsoft 365 Defender portal, navigate to Threat analytics from the left-hand navigation. For each threat, you’ll be able to view a score that reflects the severity of misconfigurations the attacker exploited and the number of affected assets as shown in Figure 2.
Figure 2: View a graph of your organization's score over time in the threat overview tab.
View and act on recommended actions from an incident or a threat analytics report
View the list of recommended posture controls directly from the recommended actions tab within the incident or threat analytics page in Microsoft 365 Defender.
Figure 3: Posture recommendation actions within Incident.
The new threat-informed security posture recommendations in Microsoft 365 Defender make it easy for defenders to identify the highest priority security controls that will help them protect their organization from being affected by the same threats and attack techniques repeatedly. It’s a new, automated approach to better understand the direct impact that misconfiguration can have on the environment – and how to fix it.
Learn more
- To start using these capabilities turn on preview in Microsoft 365 Defender.
- Check out our documentation to get started today
- Go to our website to learn more about Microsoft 365 Defender
Published on:
Learn moreRelated posts
Monthly news - November 2024
Microsoft Defender XDRMonthly newsNovember 2024 Edition This is our monthly "What's new" blog post, summarizing product updates and v...
Monthly news - August 2024
Microsoft Defender XDRMonthly newsAugust 2024 Edition This is our monthly "What's new" blog post, summarizing product updates and var...
Defender for Identity: the critical role of identities in automatic attack disruption
In today's digital landscape, cyber-threats are becoming increasingly sophisticated and frequent. Advanced attacks are often multi-workload an...
New Security Copilot skill: Identity Summary
“Can you summarize Defender insights about this user over the last two days?” Microsoft’s latest innovation for Copilot for Security, sim...
Demystify potential data leaks with Insider Risk Management insights in Defender XDR
In today's complex security landscape, understanding and mitigating data exfiltration risks is more critical than ever. Earlier this year, we ...
Monthly news - October 2024
Microsoft Defender XDRMonthly newsOctober 2024 Edition This is our monthly "What's new" blog post, summarizing product updates and va...
AI-Driven Guided Response for SOCs with Microsoft Copilot for Security
In today's evolving cybersecurity landscape, security operation centers (SOCs) are constantly bombarded with incidents ranging from minor aler...
Identity Summary: New Security Copilot skill within Defender XDR
“Can you summarize Defender insights about this user over the last two days?” Microsoft’s latest innovation for Copilot for Security, sim...
Detecting browser anomalies to disrupt attacks early
Detecting browser anomalies is crucial for early identification and prevention of cyber threats, preventing data breaches and attacks by monit...
Microsoft Defender for Identity: the critical role of identities in automatic attack disruption
In today's digital landscape, cyber-threats are becoming increasingly sophisticated and frequent. Advanced attacks are often multi-workload an...