Explore Our Microsoft Cloud Security Training →
Microsoft Defender for Endpoint: A Powerful Tool for SOC Analysts
As a SOC analyst or incident responder, you often face the challenge of dealing with compromised devices in your organization’s network. One powerful tool to help you manage these situations is Microsoft Defender for Endpoint (MDE). In this guide, we will walk you through the process of isolating compromised devices, running live response sessions for forensic investigation, collecting investigation packages, using Advanced Hunting to trace attacker activity, remediation, and releasing devices from isolation.
Isolating Compromised Devices
To isolate a compromised device via the Defender portal, navigate to the ‘Device Management’ section and select the affected device. Under ‘Device Actions’, click on ‘Quarantine’. This action will prevent the device from communicating with other devices in your network.
Running Live Response Sessions
After isolating the device, start a live response session to collect more information for forensic investigation. To initiate a live response session, go to ‘Incidents and Threats’, select the incident related to the compromised device, and click on ‘Start Live Response’.
Collecting Investigation Packages
During the live response session, you can collect an investigation package for further analysis. To do this, navigate to the ‘Artifacts’ tab in the live response session and click on ‘Download Artifact’. This will download a .zip file containing various logs and artifacts from the compromised device.
Using Advanced Hunting
To trace the activity of attackers, use Advanced Hunting queries. These queries allow you to search for specific indicators of compromise (IOCs) across your entire organization. To access Advanced Hunting, go to ‘Investigate’ and select ‘Queries’.
Remediation and Releasing Devices from Isolation
Once the compromised device has been remediated, you can release it from isolation. To do this, navigate to the ‘Device Management’ section, select the isolated device, and click on ‘Release from Quarantine’. The device will now be able to communicate with other devices in your network.
Stay Ahead of Threats with ITP Training
Mastering Microsoft Defender for Endpoint is crucial for maintaining a secure and productive IT environment. To enhance your skills, consider our Microsoft Cloud Security Training, which covers MDE, MDI, MDO365, MDCA, XDR, Sentinel, Purview, and KQL.
Explore Our Microsoft Cloud Security Training →
Written by Mohammed Akhter
Founder of ITP Training. 50,000+ students trained across 30+ countries in Microsoft endpoint and cloud security. Learn more →
