I enabled Microsoft Defender Attack Disruption and its automatic account-disablement capability. Separately, my KQL identifies accounts that Defender has already disabled, giving the analyst evidence of response actions to include in the investigation.
Viewed
UK Water Utility
Use native containment with visibility of its actions
Extend Defender Live Response with PowerShell and KQL
Return to the full story ←