Interactive investigation

Investigate a compromised cloud workload with Defender for Cloud

Correlate workload alerts and posture findings to contain a compromised VM and remove the attack path that exposed it.

DifficultyIntermediateEstimated time35 minPrimary domainMitigate threats using Microsoft Defender for Cloud

Scenario briefing

Defender for Cloud raises alerts for suspicious authentication, a crypto-mining process, and unusual Key Vault access involving an internet-facing Azure VM. The workload belongs to a production analytics application and uses a managed identity with access to several cloud resources.

Mission

Validate the compromise, reconstruct the workload and control-plane activity, determine the affected resources, contain the attacker while preserving evidence, and remediate the posture weaknesses that created the attack path.

Products

Microsoft Defender for CloudDefender for ServersAzure Resource ManagerMicrosoft Sentinel
01

Ready to investigate?

Evidence stays closed until you choose to inspect it. Each decision reveals feedback; later stages unlock as you progress.