Launching threat analytics for Microsoft 365 Defender

Published Mar 24 2021 08:48 AM 6,001 Views
Microsoft

Threat analytics is Microsoft 365 Defender’s in-product threat intelligence (TI) solution designed to help defenders like you to efficiently understand, prevent, identify, and stop emerging threats. It provides a unique combination of in-depth TI analysis and reports from expert Microsoft security researchers, and consolidated data showing your organization’s security posture relative to the threats. Threat analytics helps you respond to and minimize the impact of active attacks.

 

As part of a unified extended detection and response (XDR) experience in Microsoft 365 Defender, threat analytics is now available for public preview. It includes better data coverage, incident management across security pillars, automatic investigation and remediation, and cross-domain hunting capabilities.  Microsoft 365 Defender threat analytics is available for Microsoft Defender for Office 365 and Microsoft Defender for Endpoint users.

 

If you’re familiar with threat analytics in Microsoft Defender for Endpoint, you’ll be excited to know that the integrated experience you’ll see in Microsoft 365 Defender threat analytics takes your report consumption to another level.

 

What’s new?

Threat analytics for Microsoft 365 Defender introduces:

 

  • Better data coverage between Microsoft Defender for Endpoint and Microsoft Defender for Office 365, making combined incident management, automatic investigation, remediation, and proactive or reactive threat hunting across-the domain possible.
  • Email-related detections and mitigations from Microsoft Defender for Office 365, in addition to the endpoint data already available from Microsoft Defender for Endpoint.
  • A view of threat-related incidents that aggregate alerts into end-to-end attack stories across Microsoft Defender for Endpoint and Microsoft Defender for Office 365 to reduce the work queue, as well as simplify and speed up your investigation.
  • Attack attempts detected and blocked by Microsoft Defender for Office 365. You can also see data that you can use to drive preventive actions that mitigate the risk of further exposure and increase resilience.
  • Enhanced design that puts actionable information in the spotlight to help you quickly identify data to urgently focus on, investigate, and leverage from the reports. 

 

Dana_Bargury_1-1616600125718.png

 

What’s in each report?

With each threat analytics report, you’ll find:

  • Detailed analyst report—deep-dive analysis, MITRE techniques, detection details, recommended mitigations, and advance hunting queries that expand detection coverage.
  • Active alerts and incidents. 
  • Impacted assets, including your devices and mailboxes.
  • Prevented email attempts, indicating whether you were a target of this threat even if the email has been blocked before delivery or delivered to the junk mail folder.
  • Mitigations and their statuses, with options to investigate further and remediate weaknesses using threat and vulnerability management (please note that email related mitigations are found in the analyst report).

 

How do I get there?

  • Threat analytics can be accessed from the Microsoft 365 security center navigation bar.
  • When a new threat report is published or updated, you’ll get a badge in the navigation bar.
  • A dedicated threat analytics card has also been added to the Microsoft 365 security center dashboard, so you can track the threats that are active on your network.

 

Dana_Bargury_2-1616600125754.png

 

Ready to check it out? Explore these threat analytics reports.

Solorigate supply chain attack

Microsoft continues to work with partners and customers to expand our knowledge of the threat actor behind the nation-state cyberattacks that compromised the supply chain of SolarWinds and impacted multiple other organizations. Microsoft previously used ‘Solorigate’ as the primary designation for the actor, but moving forward, we want to place appropriate focus on the actors behind the sophisticated attacks, rather than one of the examples of malware used by the actors. Microsoft Threat Intelligence Center (MSTIC) has named the actor behind the attack against SolarWinds, the SUNBURST backdoor, TEARDROP malware, and related components as NOBELIUM. As we release new content and analysis, we will use NOBELIUM to refer to the actor and the campaign of attacks.

 

This report about the sophisticated attack details how NOBELIUM inserted malicious code into a supply chain development process. A malicious software class was included among many other legitimate classes and then signed with a legitimate certificate. The resulting binary included a backdoor and was then discreetly distributed into targeted organizations. This attack was discovered as part of an ongoing investigation.

 

Emotet breaks hiatus with spike in cybercrime activity

Understand how Emotet operators have started to ramp up activity starting July 2020. Notable for their involvement in Ryuk ransomware distribution, Emotet operators are back with basically the same goals, utilizing similar lure themes and macro-enabled documents. Despite the recent take-down which has interrupted Emotet, your security operation centers should continuously monitor Emotet-related alerts in your antivirus and EDR solutions. Secondary payloads delivered by Emotet prior to the take-down remain a serious and real threat to your network.

 

BazaLoader: Foothold for ransomware

Possibly tied to the same cybercriminals leveraging Trickbot infrastructure, these campaigns appear to be part of ongoing attempts to shift to other entry vectors. Started in late October 2020, these campaigns use phishing emails that take recipients through link chains to implant BazaLoader. Unsurprisingly, the new implant brings in potent tools like Cobalt Strike, which make persistent, direct human attack activity possible. Microsoft's security solutions remain effective against this threat, regardless of the recent BazaLoader activities that we've observed this month. Use advanced hunting to proactively hunt for this threat in your Microsoft 365 security portal (Microsoft 365 Defender) or Microsoft Security Center portal (Microsoft Defender for Endpoint).

 

IcedID's frosty arrival can lead to data theft

Get your shields up by learning about this modular banking trojan’s modus operandi and how Microsoft 365 Defender can help detect and stop IcedID campaigns at multiple points along the attack chain and across domains, including the very start.

 

2 Comments
New Contributor

Hi, 

Thanks for the update. 

Can we manually rescan the asset for reported vulnerability?

Respected Contributor

@Dana_Bargury is there any way to add additional threat intelligence feeds to M365 Defender?

%3CLINGO-SUB%20id%3D%22lingo-sub-2232909%22%20slang%3D%22en-US%22%3ERe%3A%20Launching%20threat%20analytics%20for%20Microsoft%20365%20Defender%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2232909%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20for%20the%20update.%26nbsp%3B%3C%2FP%3E%3CP%3ECan%20we%20manually%20rescan%20the%20asset%20for%20reported%20vulnerability%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2232724%22%20slang%3D%22en-US%22%3ELaunching%20threat%20analytics%20for%20Microsoft%20365%20Defender%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2232724%22%20slang%3D%22en-US%22%3E%3CP%3EThreat%20analytics%20is%20Microsoft%20365%20Defender%E2%80%99s%20in-product%20threat%20intelligence%20(TI)%20solution%20designed%20to%20help%20defenders%20like%20you%20to%20efficiently%20understand%2C%20prevent%2C%20identify%2C%20and%20stop%20emerging%20threats.%20It%20provides%20a%20unique%20combination%20of%20in-depth%20TI%20analysis%20and%20reports%20from%20expert%20Microsoft%20security%20researchers%2C%20and%20consolidated%20data%20showing%20your%20organization%E2%80%99s%20security%20posture%20relative%20to%20the%20threats.%20Threat%20analytics%20helps%20you%20respond%20to%20and%20minimize%20the%20impact%20of%20active%20attacks.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAs%20part%20of%20a%20unified%20extended%20detection%20and%20response%20(XDR)%20experience%20in%20Microsoft%20365%20Defender%2C%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmicrosoft-365%2Fsecurity%2Fdefender%2Fthreat-analytics%3Fview%3Do365-worldwide%22%20rel%3D%22noopener%20noreferrer%22%20target%3D%22_blank%22%3Ethreat%20analytics%3C%2FA%3E%20is%20now%20available%20for%20public%20preview.%20It%20includes%20better%20data%20coverage%2C%20incident%20management%20across%20security%20pillars%2C%20automatic%20investigation%20and%20remediation%2C%20and%20cross-domain%20hunting%20capabilities.%20%26nbsp%3BMicrosoft%20365%20Defender%20threat%20analytics%20is%20available%20for%20Microsoft%20Defender%20for%20Office%20365%20and%20Microsoft%20Defender%20for%20Endpoint%20users.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20you%E2%80%99re%20familiar%20with%20threat%20analytics%20in%20Microsoft%20Defender%20for%20Endpoint%2C%20you%E2%80%99ll%20be%20excited%20to%20know%20that%20the%20integrated%20experience%20you%E2%80%99ll%20see%20in%20Microsoft%20365%20Defender%20threat%20analytics%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmicrosoft-365%2Fsecurity%2Fdefender%2Fthreat-analytics-analyst-reports%3Fview%3Do365-worldwide%22%20rel%3D%22noopener%20noreferrer%22%20target%3D%22_blank%22%3Etakes%20your%20report%20consumption%20to%20another%20level%3C%2FA%3E.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhat%E2%80%99s%20new%3F%3C%2FP%3E%3CP%3EThreat%20analytics%20for%20Microsoft%20365%20Defender%20introduces%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3EBetter%20data%20coverage%20between%20Microsoft%20Defender%20for%20Endpoint%26nbsp%3Band%20Microsoft%20Defender%20for%20Office%20365%2C%20making%20combined%20incident%20management%2C%20automatic%20investigation%2C%20remediation%2C%20and%20proactive%20or%20reactive%20threat%20hunting%20across-the%20domain%20possible.%20Email-related%20detections%20and%20mitigations%20from%20Microsoft%20Defender%20for%20Office%20365%2C%20in%20addition%20to%20the%20endpoint%20data%20already%20available%20from%20Microsoft%20Defender%20for%20Endpoint.%20A%20view%20of%20threat-related%20incidents%20that%20aggregate%20alerts%20into%20end-to-end%20attack%20stories%20across%20Microsoft%20Defender%20for%20Endpoint%20and%20Microsoft%20Defender%20for%20Office%20365%26nbsp%3Bto%20reduce%20the%20work%20queue%2C%20as%20well%20as%20simplify%20and%20speed%20up%20your%20investigation.%20Attack%20attempts%20detected%20and%20blocked%20by%20Microsoft%20Defender%20for%20Office%20365.%20You%20can%20also%20see%20data%20that%20you%20can%20use%20to%20drive%20preventive%20actions%20that%20mitigate%20the%20risk%20of%20further%20exposure%20and%20increase%20resilience.%20Enhanced%20design%20that%20puts%20actionable%20information%20in%20the%20spotlight%20to%20help%20you%20quickly%20identify%20data%20to%20urgently%20focus%20on%2C%20investigate%2C%20and%20leverage%20from%20the%20reports.%26nbsp%3B%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhat%E2%80%99s%20in%20each%20report%3F%3C%2FP%3E%3CP%3EWith%20each%20threat%20analytics%20report%2C%20you%E2%80%99ll%20find%3A%3C%2FP%3EDetailed%20analyst%20report%E2%80%94deep-dive%20analysis%2C%20MITRE%20techniques%2C%20detection%20details%2C%20recommended%20mitigations%2C%20and%20advance%20hunting%20queries%20that%20expand%20detection%20coverage.%20Active%20alerts%20and%20incidents.%26nbsp%3B%20Impacted%20assets%2C%20including%20your%20devices%20and%20mailboxes.%20Prevented%20email%20attempts%2C%20indicating%20whether%20you%20were%20a%20target%20of%20this%20threat%20even%20if%20the%20email%20has%20been%20blocked%20before%20delivery%20or%20delivered%20to%20the%20junk%20mail%20folder.%20Mitigations%20and%20their%20statuses%2C%20with%20options%20to%20investigate%20further%20and%20remediate%20weaknesses%20using%20threat%20and%20vulnerability%20management%20(please%20note%20that%20email%20related%20mitigations%20are%20found%20in%20the%20analyst%20report).%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHow%20do%20I%20get%20there%3F%3C%2FP%3EThreat%20analytics%20can%20be%20accessed%20from%20the%20Microsoft%20365%20security%20center%20navigation%20bar.%20When%20a%20new%20threat%20report%20is%20published%20or%20updated%2C%20you%E2%80%99ll%20get%20a%20badge%20in%20the%20navigation%20bar.%20A%20dedicated%20threat%20analytics%20card%20has%20also%20been%20added%20to%20the%20Microsoft%20365%20security%20center%20dashboard%2C%20so%20you%20can%20track%20the%20threats%20that%20are%20active%20on%20your%20network.%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EReady%20to%20check%20it%20out%3F%20Explore%20these%20threat%20analytics%20reports.%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fnam06.safelinks.protection.outlook.com%2F%3Furl%3Dhttps%253A%252F%252Fsecurity.microsoft.com%252Fthreatanalytics3%252F2b74f636-146e-48dd-94f6-5cb5132467ca%252Foverview%26amp%3Bdata%3D04%257C01%257CDana.Bargury%2540microsoft.com%257C0fd52c89653941bf6c5d08d8b0d75843%257C72f988bf86f141af91ab2d7cd011db47%257C0%257C0%257C637453786235488399%257CUnknown%257CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%253D%257C1000%26amp%3Bsdata%3DHwCguEbjakgOCtbCHelQzeErHxzM3S77cN4wseFqF3g%253D%26amp%3Breserved%3D0%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%20target%3D%22_blank%22%3ESolorigate%20supply%20chain%20attack%3C%2FA%3E%3C%2FP%3E%3CP%3EMicrosoft%20continues%20to%20work%20with%20partners%20and%20customers%20to%20expand%20our%20knowledge%20of%20the%20threat%20actor%20behind%20the%20nation-state%20cyberattacks%20that%20compromised%20the%20supply%20chain%20of%20SolarWinds%20and%20impacted%20multiple%20other%20organizations.%20Microsoft%20previously%20used%20%E2%80%98Solorigate%E2%80%99%20as%20the%20primary%20designation%20for%20the%20actor%2C%20but%20moving%20forward%2C%20we%20want%20to%20place%20appropriate%20focus%20on%20the%20actors%20behind%20the%20sophisticated%20attacks%2C%20rather%20than%20one%20of%20the%20examples%20of%20malware%20used%20by%20the%20actors.%20Microsoft%20Threat%20Intelligence%20Center%20(MSTIC)%20%3CA%20href%3D%22https%3A%2F%2Fwww.microsoft.com%2Fsecurity%2Fblog%2F2021%2F03%2F04%2Fgoldmax-goldfinder-sibot-analyzing-nobelium-malware%2F%22%20rel%3D%22noopener%20noreferrer%22%20target%3D%22_blank%22%3Ehas%20named%20the%20actor%3C%2FA%3E%20behind%20the%20attack%20against%20SolarWinds%2C%20the%20SUNBURST%20backdoor%2C%20TEARDROP%20malware%2C%20and%20related%20components%20as%20NOBELIUM.%20As%20we%20release%20new%20content%20and%20analysis%2C%20we%20will%20use%20NOBELIUM%20to%20refer%20to%20the%20actor%20and%20the%20campaign%20of%20attacks.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20report%20about%20the%20sophisticated%20attack%20details%20how%20NOBELIUM%20inserted%20malicious%20code%20into%20a%20supply%20chain%20development%20process.%20A%20malicious%20software%20class%20was%20included%20among%20many%20other%20legitimate%20classes%20and%20then%20signed%20with%20a%20legitimate%20certificate.%20The%20resulting%20binary%20included%20a%20backdoor%20and%20was%20then%20discreetly%20distributed%20into%20targeted%20organizations.%20This%20attack%20was%20discovered%20as%20part%20of%20an%20ongoing%20investigation.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fnam06.safelinks.protection.outlook.com%2F%3Furl%3Dhttps%253A%252F%252Fsecurity.microsoft.com%252Fthreatanalytics3%252F2d1462d0-9aba-4e0b-927d-ba0dea0b47c2%252Fanalystreport%26amp%3Bdata%3D04%257C01%257CDana.Bargury%2540microsoft.com%257C0fd52c89653941bf6c5d08d8b0d75843%257C72f988bf86f141af91ab2d7cd011db47%257C0%257C0%257C637453786235478440%257CUnknown%257CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%253D%257C1000%26amp%3Bsdata%3DrNs%252B%252Fsk%252BM2Wvuab%252Ftt1vDKVzAUq0gJsr63RTSGmEUk4%253D%26amp%3Breserved%3D0%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%20target%3D%22_blank%22%3EEmotet%20breaks%20hiatus%20with%20spike%20in%20cybercrime%20activity%3C%2FA%3E%3C%2FP%3E%3CP%3EUnderstand%20how%20Emotet%20operators%20have%20started%20to%20ramp%20up%20activity%20starting%20July%202020.%20Notable%20for%20their%20involvement%20in%20Ryuk%20ransomware%20distribution%2C%20Emotet%20operators%20are%20back%20with%20basically%20the%20same%20goals%2C%20utilizing%20similar%20lure%20themes%20and%20macro-enabled%20documents.%20Despite%20the%20recent%20take-down%20which%20has%20interrupted%20Emotet%2C%20your%20security%20operation%20centers%20should%20continuously%20monitor%20Emotet-related%20alerts%20in%20your%20antivirus%20and%20EDR%20solutions.%20Secondary%20payloads%20delivered%20by%20Emotet%20prior%20to%20the%20take-down%20remain%20a%20serious%20and%20real%20threat%20to%20your%20network.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fnam06.safelinks.protection.outlook.com%2F%3Furl%3Dhttps%253A%252F%252Fsecurity.microsoft.com%252Fthreatanalytics3%252F93c50031-5d2b-4d2d-bd7e-abdee9ea4418%252Foverview%26amp%3Bdata%3D04%257C01%257CDana.Bargury%2540microsoft.com%257C0fd52c89653941bf6c5d08d8b0d75843%257C72f988bf86f141af91ab2d7cd011db47%257C0%257C0%257C637453786235478440%257CUnknown%257CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%253D%257C1000%26amp%3Bsdata%3DnhZkJ%252FjmYkON6c1VAoaDQZJGZ8jHqOjGbtHGI%252BVqtf4%253D%26amp%3Breserved%3D0%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%20target%3D%22_blank%22%3EBazaLoader%3A%20Foothold%20for%20ransomware%3C%2FA%3E%3C%2FP%3E%3CP%3EPossibly%20tied%20to%20the%20same%20cybercriminals%20leveraging%20Trickbot%20infrastructure%2C%20these%20campaigns%20appear%20to%20be%20part%20of%20ongoing%20attempts%20to%20shift%20to%20other%20entry%20vectors.%20Started%20in%20late%20October%202020%2C%20these%20campaigns%20use%20phishing%20emails%20that%20take%20recipients%20through%20link%20chains%20to%20implant%20BazaLoader.%20Unsurprisingly%2C%20the%20new%20implant%20brings%20in%20potent%20tools%20like%20Cobalt%20Strike%2C%20which%20make%20persistent%2C%20direct%20human%20attack%20activity%20possible.%20Microsoft's%20security%20solutions%20remain%20effective%20against%20this%20threat%2C%20regardless%20of%20the%20recent%20BazaLoader%20activities%20that%20we've%20observed%20this%20month.%20Use%20advanced%20hunting%20to%20proactively%20hunt%20for%20this%20threat%20in%20your%20Microsoft%20365%20security%20portal%20(Microsoft%20365%20Defender)%20or%20Microsoft%20Security%20Center%20portal%20(Microsoft%20Defender%20for%20Endpoint).%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fsecuritycenter.windows.com%2Fthreatanalytics3%2F5cd2bcc2-fbe1-463f-ab5a-cd5696a629e6%2Foverview%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%20target%3D%22_blank%22%3EIcedID's%20frosty%20arrival%20can%20lead%20to%20data%20theft%3C%2FA%3E%3C%2FP%3E%3CP%3EGet%20your%20shields%20up%20by%20learning%20about%20this%20modular%20banking%20trojan%E2%80%99s%20modus%20operandi%20and%20how%20Microsoft%20365%20Defender%20can%20help%20detect%20and%20stop%20IcedID%20campaigns%20at%20multiple%20points%20along%20the%20attack%20chain%20and%20across%20domains%2C%20including%20the%20very%20start.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-2232724%22%20slang%3D%22en-US%22%3E%3CP%3EEmpower%20your%20SecOps%20team%20with%20a%20threat%20intelligence%20solution%20that%20gives%20actionable%20reports%20on%20the%20latest%20threats%20relative%20to%20your%20unique%20environment%2C%20and%20insights%20on%20the%20best%20ways%20to%20protect%20your%20organization.%3C%2FP%3E%3CP%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2435474%22%20slang%3D%22en-US%22%3ERe%3A%20Launching%20threat%20analytics%20for%20Microsoft%20365%20Defender%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2435474%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F769425%22%20target%3D%22_blank%22%3E%40Dana_Bargury%3C%2FA%3E%26nbsp%3Bis%20there%20any%20way%20to%20add%20additional%20threat%20intelligence%20feeds%20to%20M365%20Defender%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E
Co-Authors
Version history
Last update:
‎Mar 24 2021 01:32 PM
Updated by:
www.000webhost.com