A Microsoft Defender XDR feature that links signals into a high-confidence incident and, while ransomware, business email compromise or a similar attack is still in progress, contains the affected accounts and devices on its own. Security staff can reverse these actions.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Automatic attack disruption in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Defender XDR
Brings Defender products such as Cloud Apps, Identity, Office 365 and Endpoint together, joining their signals into incidents that span the time before and after a breach. Includes advanced hunting and automatic disruption of attacks.
- Incident
A case that Microsoft Defender XDR or Microsoft Sentinel builds by correlating several alerts that look like parts of one attack. It lists the assets involved and the evidence, and analysts can assign it and update its status as they investigate.
- BEC
Business email compromise is a scam where criminals pretend to be someone trusted, perhaps a finance officer, customer or partner, so that money is moved, payments signed off or data handed over. Plan 1 of Defender for Office 365 defends against it.
- CONTAINS
Searches columns with a full-text index for words, phrases, prefixes, inflected forms or synonyms; you use it as a predicate in
WHERE. - AGDLP
Nesting pattern: users go into global groups, which go into domain local groups, which receive the permissions. AGUDLP adds universal groups for forests with several domains.
Related terms
- Contain user
Stops a compromised account's network logons and lateral movement by pushing a policy to every onboarded device. Automatic attack disruption uses this Defender for Endpoint action, which you can reverse from the Action center or from the user's page.
- DisruptionAndResponseEvents
Lets you query, in advanced hunting, what automatic attack disruption has done across Microsoft Defender XDR. It is still a preview feature.