Interactive investigation
Investigate a compromised cloud workload with Defender for Cloud
Correlate workload alerts and posture findings to contain a compromised VM and remove the attack path that exposed it.
Scenario briefing
Defender for Cloud raises alerts for suspicious authentication, a crypto-mining process, and unusual Key Vault access involving an internet-facing Azure VM. The workload belongs to a production analytics application and uses a managed identity with access to several cloud resources.
Mission
Validate the compromise, reconstruct the workload and control-plane activity, determine the affected resources, contain the attacker while preserving evidence, and remediate the posture weaknesses that created the attack path.
Products
Ready to investigate?
Evidence stays closed until you choose to inspect it. Each decision reveals feedback; later stages unlock as you progress.