Raphael · @0x3e4
44 followers · 137 posts · Server shitcoin.land
Nicola Ferrini · @nicferr
41 followers · 2174 posts · Server mastodon.uno

for Business è una soluzione di sicurezza degli endpoint progettata appositamente per le piccole e medie imprese (fino a 300 dipendenti). Con questa soluzione di sicurezza degli endpoint, i dispositivi dell’azienda sono meglio protetti da ransomware, malware, phishing e altre minacce. In questa sessione verrà mostrato come Microsoft Defender for Business sia capace di difender i nostri dispositivi. youtube.com/watch?v=a_qHsvdIH1

#microsoft #defender #cybersecurity #MDE

Last updated 1 year ago

Nicola Ferrini · @nicferr
39 followers · 2074 posts · Server mastodon.uno

for Business è una soluzione di sicurezza degli endpoint progettata appositamente per le piccole e medie imprese (fino a 300 dipendenti). Con questa soluzione di sicurezza degli endpoint, i dispositivi dell’azienda sono meglio protetti da ransomware, malware, phishing e altre minacce. In questa sessione verrà mostrato come Microsoft Defender for Business sia capace di difender i nostri dispositivi. youtube.com/watch?v=a_qHsvdIH1

#microsoft #defender #cybersecurity #MDE

Last updated 1 year ago

Nicola Ferrini · @nicferr
39 followers · 1988 posts · Server mastodon.uno

for Business è una soluzione di sicurezza degli endpoint progettata appositamente per le piccole e medie imprese (fino a 300 dipendenti). Con questa soluzione di sicurezza degli endpoint, i dispositivi dell’azienda sono meglio protetti da ransomware, malware, phishing e altre minacce. In questa sessione verrà mostrato come Microsoft Defender for Business sia capace di difender i nostri dispositivi. youtube.com/watch?v=a_qHsvdIH1

#microsoft #defender #cybersecurity #MDE

Last updated 1 year ago

Nicola Ferrini · @nicferr
39 followers · 1876 posts · Server mastodon.uno

for Business è una soluzione di sicurezza degli endpoint progettata appositamente per le piccole e medie imprese (fino a 300 dipendenti). Con questa soluzione di sicurezza degli endpoint, i dispositivi dell’azienda sono meglio protetti da ransomware, malware, phishing e altre minacce. In questa sessione verrà mostrato come Microsoft Defender for Business sia capace di difender i nostri dispositivi. youtube.com/watch?v=a_qHsvdIH1

#microsoft #defender #cybersecurity #MDE

Last updated 1 year ago

Nicola Ferrini · @nicferr
39 followers · 1778 posts · Server mastodon.uno

for Business è una soluzione di sicurezza degli endpoint progettata appositamente per le piccole e medie imprese (fino a 300 dipendenti). Con questa soluzione di sicurezza degli endpoint, i dispositivi dell’azienda sono meglio protetti da ransomware, malware, phishing e altre minacce. In questa sessione verrà mostrato come Microsoft Defender for Business sia capace di difender i nostri dispositivi. youtube.com/watch?v=a_qHsvdIH1

#microsoft #defender #cybersecurity #MDE

Last updated 1 year ago

Joan Leon · @nucliweb
98 followers · 118 posts · Server webperf.social

I'm excited to announce that I'm officially a Cloudinary ambassador 😊

#cloudinaryambassadors #Image #ImagePerf #MDE #webperf

Last updated 1 year ago

Fabian Bader · @fabian_bader
892 followers · 345 posts · Server infosec.exchange

Microsoft Defender for Endpoint Security Feature Bypass Vulnerability
CVE-2023-21809

It's enough to update your AV signatures to a version higher than 1.379.200.0

#mdav #MDE

Last updated 1 year ago

Fabian Bader · @fabian_bader
890 followers · 344 posts · Server infosec.exchange

Microsoft 365 Defender now supports NRT (Near RealTime) custom detections.

See docs for known limitations
learn.microsoft.com/en-us/micr

#MDE #M365D #NRT #customdetection

Last updated 1 year ago

Fabian Bader · @fabian_bader
890 followers · 343 posts · Server infosec.exchange

As of 07.03.2023 (Release of signature 1.383.1159.0) tamper protection is no longer enforcing "Allow Scanning Network Files".

If you still want this to be enabled, make sure your Intune or GPO configuration has this value set.

#mdav #MDE #M365D #tamperprotection

Last updated 1 year ago

Sentry23 · @Sentry23
166 followers · 314 posts · Server infosec.exchange

if anybody is interested.

hunting query for recent variant.

(still tuning some parameters as it can be a bit slow, and file size filter can probably be a lot bigger)

EmailAttachmentInfo
| where FileType == "zip" and FileName endswith_cs "zip" and FileSize > 100000
| join kind=inner (EmailEvents | where EmailDirection == "Inbound" and SenderFromAddress !endswith "[mydomain.com]" and (Subject startswith_cs "Re:" or Subject startswith_cs "Fwd:")) on NetworkMessageId, SenderFromAddress, RecipientEmailAddress
| join DeviceFileEvents on SHA256
| distinct SenderFromAddress, RecipientEmailAddress, FileName, Subject, SHA1
| invoke FileProfile()
| where GlobalPrevalence < 15

#MDE #KQL #emotet

Last updated 1 year ago

The team collected a 3-phase guide & implementation checklists against :

1️⃣ Prepare recovery plan
2️⃣ Protect privileged roles + improve detection & response
3️⃣ Improve identity, e-mail & endpoint security

learn.microsoft.com/en-us/secu

#microsoft365defender #ransomware #M365D #mdo #MDE #azuread

Last updated 1 year ago

F0rm4t · @F0rm4t
36 followers · 41 posts · Server infosec.exchange

The new support for mixed-licensing scenarios in Defender for Endpoint () enables you to properly limit the scope of Plan 1 or Plan 2 features to your client devices.

learn.microsoft.com/en-us/micr

#microsoft #MDE #microsoft365 #M365D

Last updated 1 year ago

Fabian Bader · @fabian_bader
880 followers · 334 posts · Server infosec.exchange

What's new in Microsoft Defender Endpoint this month?

Mixed-licensing scenarios are officially supported

learn.microsoft.com/en-us/micr

#MDE #m365

Last updated 1 year ago

F0rm4t · @F0rm4t
36 followers · 39 posts · Server infosec.exchange
Raphael · @0x3e4
33 followers · 108 posts · Server shitcoin.land
Fabian Bader · @fabian_bader
877 followers · 331 posts · Server infosec.exchange

Update on the Server Antivirus Exclusions

Microsoft finally removed the recommendation to exclude PowerShell.exe and w3wp.exe and two others from the official documentation

techcommunity.microsoft.com/t5

#exchange #mdav #MDE

Last updated 1 year ago

The new automatic attack disruption feature combines the benefits of for Identity () & Defender for Endpoint () and stops adversaries at an early stage:

✓ Block compromised accounts
✓ Isolate infected devices

learn.microsoft.com/en-us/micr

#microsoftdefender #MDI #MDE

Last updated 1 year ago

Fabian Bader · @fabian_bader
864 followers · 314 posts · Server infosec.exchange

100% pure cloud based management of devices is coming closer.

See the latest Microsoft blog "Push ASR rules with Security Settings Management on Microsoft Defender for Endpoint managed devices"

techcommunity.microsoft.com/t5

#MDE #asr #mdav

Last updated 2 years ago