Interactive investigation

Investigate and contain a ransomware attempt with Defender for Endpoint

Use endpoint evidence to reconstruct execution, find lateral movement, contain affected devices, and recover without destroying forensic value.

DifficultyIntermediateEstimated time35 minPrimary domainRespond to security incidents

Scenario briefing

Defender XDR correlates suspicious Office child-process activity, credential dumping, remote service creation, and shadow-copy deletion across a finance workstation and two servers. Files are not yet encrypted, but the observed sequence matches ransomware preparation.

Mission

Reconstruct the attack, determine which devices and identities are affected, interrupt lateral movement before encryption, preserve useful evidence, and validate a safe recovery path.

Products

Microsoft Defender for EndpointMicrosoft Defender XDRMicrosoft Entra IDAdvanced Hunting
01

Ready to investigate?

Evidence stays closed until you choose to inspect it. Each decision reveals feedback; later stages unlock as you progress.