Microsoft Stops Ransomware Attack in 128 Seconds with New Device Isolation Feature
Microsoft's Defender has successfully disrupted a ransomware attack in just 128 seconds at QNET, a global direct-selling company. The attack was initiated by an attacker using a legitimate Windows tool on a compromised endpoint to retrieve a malicious remote payload.
The attacker employed a 'living-off-the-land' (LOL) technique that evades traditional containment methods. However, Microsoft Defender's attack disruption feature automatically enforced device isolation, cutting off the attack chain before the second-stage payload could establish persistence or move beyond the host.
Device isolation is a new response action in Microsoft Defender that extends autonomous protection directly to compromised endpoints. It isolates the device from external network connectivity while maintaining access to required security services like Microsoft Defender for Endpoint.
The incident highlights the growing threat of high-severity attacks that begin with initial access directly on the device, rather than through user identity. Device isolation closes this gap by automatically correlating signals, assessing the threat, and isolating the compromised device within seconds.