What’s new in DefenderXDR? 03/26

This time, Defender XDR brings several interesting changes that have a impact on how detections, investigations, and response workflows behave. Overall the focus is less on new big elements and more on some foundational capabilities that affect day‑to‑day SecOps work. But nonetheless there are some highlights once again !

 

My personal Highlights

  • Live response library management

    • Centralized management of live response scripts and files sounds small, but it removes a lot of operational friction. Being able to upload, review, and clean up live response artifacts outside of an active session makes incident response more predictable and reusable  especially in mature SOC environments.

  • Proactive user containment (contain user)

    • Proactive user containment as part of predictive shielding is a step toward identity‑centric attack disruption. Blocking high‑risk users early, before credentials are reused at scale, can reduce blast radius, particularly in ransomware and hands‑on‑keyboard scenarios. This (and generally for predictive shielding) is one of those things where understanding the behavior really matters in my opinion.

 

Defender for Endpoint

 

Defender for Identity

 

Defender for Cloud Apps

 

Defender for Office365

 

DefenderXDR

 
Previous
Previous

Zero to Hero –What’s up with Defender for Endpoint Passive and EDR Block Mode – Complete Guide

Next
Next

Zero to Hero –How to Onboard Microsoft Defender for Endpoint for MacOS with Intune – Complete Guide