Microsoft Defender is now detecting Zerologon attacks

Microsoft has added Zerologon detection support to Microsoft Defender for Identity to enable Security Operations teams to detect attacks within the enterprise that attempt to abuse this critical s.

Microsoft Defender for Identity (formerly known as Azure Advanced Threat Protection or Azure ATP) is a cloud-based security solution designed to leverage on-premises Active Directory signals to detect and compromised identities, for advanced threats and malicious insider activity targeting a registered organization.

"Microsoft Defender for Identity can detect this vulnerability early on," said Microsoft Program Manager Daniel Naim. "It covers both aspects of exploiting and controlling the circulation of Netlogon."

Notifications that appear whenever exploit Zerologon or related activity is detected will allow SecOps teams to quickly receive information about the device or domain controller behind attack attempts.

Alerts will also provide information that can help identify targeted information if the attacks were successful.

“Finally, customers using Microsoft 365 Defender can take full advantage of the power of Microsoft Defender for Identity signals and alerts, combined with behavioral events and detections from Microsoft Defender for Naim added.

“This coordinated protection enables you to not only monitor Netlogon exploit attempts over network protocols, but also see device process and activity related to the exploit.”

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by Anastasis Vasileiadis

Translations are like women. When they are beautiful they are not faithful and when they are faithful they are not beautiful.

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).