Interactive investigation
Investigate and contain a ransomware attempt with Defender for Endpoint
Use endpoint evidence to reconstruct execution, find lateral movement, contain affected devices, and recover without destroying forensic value.
Scenario briefing
Defender XDR correlates suspicious Office child-process activity, credential dumping, remote service creation, and shadow-copy deletion across a finance workstation and two servers. Files are not yet encrypted, but the observed sequence matches ransomware preparation.
Mission
Reconstruct the attack, determine which devices and identities are affected, interrupt lateral movement before encryption, preserve useful evidence, and validate a safe recovery path.
Products
Ready to investigate?
Evidence stays closed until you choose to inspect it. Each decision reveals feedback; later stages unlock as you progress.