{"id":22533,"date":"2023-07-24T17:01:29","date_gmt":"2023-07-25T01:01:29","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2023\/07\/24\/news-16263\/"},"modified":"2023-07-24T17:01:29","modified_gmt":"2023-07-25T01:01:29","slug":"news-16263","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2023\/07\/24\/news-16263\/","title":{"rendered":"Microsoft Defender Experts for XDR helps triage, investigate, and respond to cyberthreats"},"content":{"rendered":"<p><strong>Credit to Author: Microsoft Security Experts| Date: Mon, 24 Jul 2023 16:00:00 +0000<\/strong><\/p>\n<p>It has been an eventful time since the introduction of Microsoft Security Experts.<sup>1<\/sup> We launched Defender Experts for Hunting, our first-party managed threat hunting service for customers who want Microsoft to help them proactively hunt threats across endpoints, Microsoft Office 365, cloud applications, and identity.<sup>2<\/sup> We also participated in the inaugural 2022 MITRE Engenuity ATT&amp;CK\u00ae Evaluations for Managed Services, where Microsoft demonstrated industry-leading results.<sup>3<\/sup> And finally, we announced the general availability of <a href=\"https:\/\/www.microsoft.com\/security\/business\/services\/microsoft-defender-experts-xdr\">Microsoft Defender Experts for XDR<\/a>, our first-party Managed Extended Detection and Response (MXDR) service.<sup>4<\/sup> We\u2019re excited about the launch of our newest service, so let\u2019s take a deeper look at Defender Experts for XDR and how it works.<\/p>\n<div class=\"wp-block-msxcm-cta-block\" data-moray data-bi-an=\"CTA Block\">\n<div class=\"card d-block mx-ng mx-md-0\">\n<div class=\"row no-gutters bg-gray-800 text-white\">\n<div class=\"d-flex col-md\">\n<div class=\"card-body align-self-center p-4 p-md-5\">\n<h2>Microsoft Defender Experts for XDR<\/h2>\n<div class=\"mb-3\">\n<p>Meet the new first-party MXDR services from Microsoft with end-to-end protection and expertise.<\/p>\n<\/p><\/div>\n<div class=\"link-group\"> \t\t\t\t\t\t\t<a href=\"https:\/\/www.microsoft.com\/security\/business\/services\/microsoft-defender-experts-xdr\" class=\"btn btn-primary bg-body text-body\" > \t\t\t\t\t\t\t\t<span>Learn more<\/span> \t\t\t\t\t\t\t\t<span class=\"glyph-append glyph-append-chevron-right glyph-append-xsmall\"><\/span> \t\t\t\t\t\t\t<\/a> \t\t\t\t\t\t<\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"col-md-4\"> \t\t\t\t\t<img width=\"1024\" height=\"666\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2023\/07\/Win17_CDOC_1533-1-1024x666.jpg\" class=\"card-img img-object-cover\" alt=\"Microsoft Cyber Defense Operations Center.\" decoding=\"async\" loading=\"lazy\" srcset=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2023\/07\/Win17_CDOC_1533-1-1024x666.jpg 1024w, https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2023\/07\/Win17_CDOC_1533-1-300x195.jpg 300w, https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2023\/07\/Win17_CDOC_1533-1-768x499.jpg 768w, https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2023\/07\/Win17_CDOC_1533-1.jpg 1200w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/>\t\t\t\t<\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<h2 class=\"wp-block-heading\">Defender Experts for XDR builds on Microsoft\u2019s industry-leading XDR suite<\/h2>\n<p>Industry-leading technologies serve as the backbone of any managed security service, and Defender Experts for XDR builds on the defining benchmark that Microsoft 365 Defender has set in the extended detection and response space. Microsoft was <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2021\/10\/18\/microsoft-achieves-a-leader-placement-in-forrester-wave-for-xdr\/\">named a Leader<\/a> in The Forrester New Wave\u2122: Extended Detection and Response (XDR), Q4, 2021, one of only two providers to be named a Leader.<sup>5<\/sup> <a href=\"https:\/\/www.microsoft.com\/security\/business\/threat-protection\/microsoft-365-defender\">Microsoft 365 Defender<\/a> was rated as \u201cdifferentiated\u201d in seven criteria including detection, investigation, response, and remediation. Forrester noted that our decision to regulate inputs into XDR, specifically to rich, native telemetry, yields tailored detection, investigation, response, and mitigation capabilities.<\/p>\n<p>Forrester notes that \u201cthere is a deep divide in the XDR market between those far along the path and those just starting to deliver on the vision of XDR\u201d and those mature providers \u201ccombine the best elements of their portfolios, including industry-leading products, to simplify incident response and build targeted, high-efficacy detections.\u201d<\/p>\n<p>The right and leading technologies are crucial to implementing managed services. Microsoft has a leading endpoint detection and response (EDR) solution, and while EDR is important and serves a valuable purpose, it is insufficient as the only method to protect against evolving threats.<sup>6<\/sup> In addition, \u201ctoo many tools, or worse, duplicate tools in the SOC [security operations center] need to be rationalized and managed security services like MDR [managed detection and response] are increasingly seen as not only a cost savings opportunity but also as a way to rapidly mature their capabilities.\u201d<sup>7<\/sup> With Microsoft\u2019s <a href=\"https:\/\/www.microsoft.com\/security\/business\/solutions\/extended-detection-response-xdr\">XDR solution<\/a> coupled with Defender Experts for XDR, we can deliver end-to-end protection and expertise.<\/p>\n<h2 class=\"wp-block-heading\">How Microsoft Defender Experts for XDR works<\/h2>\n<p>Our Defender Experts team delivers the essential human element that complements the power of our Microsoft 365 Defender suite. They are the tip of the spear\u2014taking unparalleled access to data and intelligence across nation-state and e-crime activity, new vulnerability data, newly observed tactics and techniques, and more to analyze and curate a hypothesis-led hunting strategy to find emerging, suspicious activities, and in turn deliver expertise to your security team immediately to help address coverage gaps and augment your overall security operations.<\/p>\n<figure class=\"wp-block-image size-large is-resized\"><img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2023\/07\/Picture1-1024x364.webp\" alt=\"Diagram that describes the four steps of the continuous security posture improvements, including triage, investigate, respond, and prevent. \" class=\"wp-image-131028 webp-format\" width=\"724\" height=\"257\" srcset=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2023\/07\/Picture1-1024x364.webp 1024w, https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2023\/07\/Picture1-300x107.webp 300w, https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2023\/07\/Picture1-768x273.webp 768w, https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2023\/07\/Picture1-1536x545.webp 1536w, https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2023\/07\/Picture1.webp 1625w\" data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2023\/07\/Picture1-1024x364.webp\"><\/figure>\n<p><em>Figure 1. This diagram describes how Microsoft conducts its four-step Defender Experts for XDR process. It starts with triage and prioritizing Microsoft 365 Defender incidents and alerts to alleviate alert fatigue. Microsoft investigates and analyzes the most critical incidents first, documenting the process and findings. In the response step, Microsoft helps contain and mitigate incidents faster by delivering step-by-step guided and managed response, with Defender Experts available on-demand by live chat. Detailed recommendations and best practices are then provided to prevent future attacks. This process delivers continuous security posture improvements around the clock.<\/em><\/p>\n<p>As an extension of your team, Defender Experts for XDR empowers you to respond with confidence. Our Defender Experts work around the clock, monitoring your environment and triaging the incidents that need immediate attention. In the event your organization is being affected by a critical incident, our team will investigate it, correlate the threat data to determine the root cause, and provide step-by-step response actions you need to take to contain and remediate the threat. You can take it further and give us permission to contain and remediate the threat for you.<\/p>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2023\/07\/Picture4-1024x591.webp\" alt=\"Screenshot of a multistage incident in the Microsoft 365 Defender dashboard. \" class=\"wp-image-131030 webp-format\" srcset=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2023\/07\/Picture4-1024x591.webp 1024w, https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2023\/07\/Picture4-300x173.webp 300w, https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2023\/07\/Picture4-768x443.webp 768w, https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2023\/07\/Picture4.webp 1497w\" data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2023\/07\/Picture4-1024x591.webp\"><\/figure>\n<p><em>Figure 2. This graphic shows a multistage incident in Microsoft 365 Defender. It includes the attack story of the active alerts related to the incident as well as the Defender Experts section that shows the guided response that includes the actions needed to resolve the incident immediately.<\/em><\/p>\n<p>This is all available to you in a turnkey experience, where you can get up and running in hours, with the help of your dedicated service delivery manager (SDM)\u2014your trusted advisor, who is available to you at any given time. And if you have any questions or need additional context on a particular incident, you can access our experts around the clock through live chat. Our detailed, real-time reporting shows you the comprehensive details of investigations into critical incidents, and how long it takes for our team to conduct the investigations on your behalf.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2023\/07\/Picture2-2.webp\" alt=\"This graphic shows an excerpt from a Defender Experts for XDR report that includes a bar graph that shows all incidents by severity and a customer&rsquo;s activity versus the Defender Experts activity. \" class=\"wp-image-131058 webp-format\" srcset=\"\" data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2023\/07\/Picture2-2.webp\"><\/figure>\n<p><em>Figure 3. The graph highlights the number of hours that a customer spent completing guided response tasks and the potential time savings a customer can realize if Defender Experts for XDR handles response on their behalf.<\/em><\/p>\n<p>\u201cDefender Experts for XDR found a shadow IT detection on the first day of service,\u201d said Mike Johnson, Global Cyber Threat and Incident Response Security Operations Center Manager at Verifone. \u201cI was impressed that they found a real issue for us so fast\u2014none of our other tools alerted us about it.\u201d<\/p>\n<p>Defender Experts for XDR also provides recommendations on how your team can be proactive to prevent the next attack and reduce the number of incidents over time to improve your security posture. \u201cOrganizations who need to augment their SOC with 24\/7 coverage and immediate access to expertise that will help them quickly triage, investigate, and respond to incidents should explore a managed XDR service,\u201c said Craig Robinson, Vice President of Security Services at IDC Research. \u201cMicrosoft\u2019s new MXDR service positions them to support the needs of organizations facing talent shortages who need to scale their security programs quickly, address coverage gaps, and protect their environment.\u201d<\/p>\n<h2 class=\"wp-block-heading\">Learn more about Microsoft Defender Experts for XDR<\/h2>\n<p>Defender Experts for XDR can quickly deliver expertise to your security teams, help address coverage gaps, and add capabilities like proactive threat hunting to augment your overall security operations. Our customers and partners have been instrumental in the development of Defender Experts for XDR and your continued trust in us drives our team to listen, learn, and adapt to meet your evolving needs. We\u2019re excited about the road ahead and look forward to being a part of your security journey and building a safer world for everyone.<\/p>\n<p>To learn more about the service, visit the <a href=\"https:\/\/www.microsoft.com\/security\/business\/services\/microsoft-defender-experts-xdr\">Microsoft Defender Experts for XDR<\/a> web page, read the <a href=\"https:\/\/learn.microsoft.com\/en-us\/microsoft-365\/security\/defender\/dex-xdr-overview?view=o365-worldwide\" target=\"_blank\" rel=\"noreferrer noopener\">Defender Experts for XDR<\/a> docs page, <a href=\"https:\/\/query.prod.cms.rt.microsoft.com\/cms\/api\/am\/binary\/RW14LHP?culture=en-us&amp;country=us\" target=\"_blank\" rel=\"noreferrer noopener\">download the datasheet<\/a>, or watch a <a href=\"https:\/\/aka.ms\/DefenderExpertsforXDRVideo\" target=\"_blank\" rel=\"noreferrer noopener\">short video<\/a>.<\/p>\n<p>To learn more about Microsoft Security solutions, visit our&nbsp;<a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\" target=\"_blank\" rel=\"noreferrer noopener\">website<\/a>.&nbsp;Bookmark the&nbsp;<a href=\"https:\/\/www.microsoft.com\/security\/blog\/\" target=\"_blank\" rel=\"noreferrer noopener\">Security blog<\/a>&nbsp;to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (<a href=\"https:\/\/www.linkedin.com\/showcase\/microsoft-security\/\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Security<\/a>) and Twitter (<a href=\"https:\/\/twitter.com\/@MSFTSecurity\" target=\"_blank\" rel=\"noreferrer noopener\">@MSFTSecurity<\/a>)&nbsp;for the latest news and updates on cybersecurity.<\/p>\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n<p><sup>1<\/sup><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2022\/05\/09\/building-a-safer-world-together-with-our-partners-introducing-microsoft-security-experts\/\">Building a safer world together with our partners\u2014introducing Microsoft Security Experts<\/a>, Vasu Jakkal. May 9, 2022.<\/p>\n<p><sup>2<\/sup><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2022\/08\/03\/microsoft-defender-experts-for-hunting-proactively-hunts-threats\/\">Microsoft Defender Experts for Hunting proactively hunts threats<\/a>, Microsoft Security Experts. August 3, 2022. <\/p>\n<p><sup>3<\/sup><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2022\/11\/09\/microsoft-defender-experts-for-hunting-demonstrates-industry-leading-protection-in-the-2022-mitre-engenuity-attck-evaluations-for-managed-services\/\">Microsoft Defender Experts for Hunting demonstrates industry-leading protection in the 2022 MITRE Engenuity ATT&amp;CK\u00ae Evaluations for Managed Services<\/a>, Ryan Kivett. November 9, 2022.<\/p>\n<p><sup>4<\/sup><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2023\/07\/10\/meet-unprecedented-security-challenges-by-leveraging-mxdr-services\/\">Meet unprecedented security challenges by leveraging MXDR services<\/a>, Microsoft Security Experts. July 10, 2023.<\/p>\n<p><sup>5<\/sup>Forrester Research, Inc., The Forrester New Wave\u2122: Extended Detection And Response (XDR) Providers, Q4 2021, Allie Mellen, Joseph Blankenship, Alexis Tatro, Peggy Dostie. October 13, 2021.<\/p>\n<p><sup>6<\/sup><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2023\/03\/02\/microsoft-is-named-a-leader-in-the-2022-gartner-magic-quadrant-for-endpoint-protection-platforms\/\">Microsoft is named a Leader in the 2022 Gartner\u00ae Magic Quadrant\u2122 for Endpoint Protection Platforms<\/a>, Rob Lefferts. March 2, 2023.<\/p>\n<p><sup>7<\/sup><a href=\"https:\/\/www.idc.com\/getdoc.jsp?containerId=US50206623\">Applying the Lessons Learned from 2022 Is Vital for Security Service Providers to Secure Growth in 2023<\/a>, Doc #US50206623, IDC. February 2023.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2023\/07\/24\/microsoft-defender-experts-for-xdr-helps-triage-investigate-and-respond-to-cyberthreats\/\">Microsoft Defender Experts for XDR helps triage, investigate, and respond to cyberthreats<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\">Microsoft Security Blog<\/a>.<\/p>\n<p><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2023\/07\/24\/microsoft-defender-experts-for-xdr-helps-triage-investigate-and-respond-to-cyberthreats\/\" target=\"bwo\" >https:\/\/blogs.technet.microsoft.com\/mmpc\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Microsoft Security Experts| Date: Mon, 24 Jul 2023 16:00:00 +0000<\/strong><\/p>\n<p>Take a closer look at how Microsoft Defender Experts for XDR works, and how it complements the power of the Microsoft 365 Defender suite. <\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2023\/07\/24\/microsoft-defender-experts-for-xdr-helps-triage-investigate-and-respond-to-cyberthreats\/\">Microsoft Defender Experts for XDR helps triage, investigate, and respond to cyberthreats<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\">Microsoft Security Blog<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10759,10378],"tags":[],"class_list":["post-22533","post","type-post","status-publish","format-standard","hentry","category-microsoft","category-security"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/22533","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=22533"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/22533\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=22533"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=22533"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=22533"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}