{"id":478,"date":"2021-08-12T19:43:33","date_gmt":"2021-08-12T19:43:33","guid":{"rendered":"https:\/\/thecloudmarathoner.com\/?p=478"},"modified":"2021-08-12T20:02:43","modified_gmt":"2021-08-12T20:02:43","slug":"azure-introduced-new-fusion-detection-for-ransomware","status":"publish","type":"post","link":"https:\/\/www.thecloudmarathoner.com\/index.php\/2021\/08\/12\/azure-introduced-new-fusion-detection-for-ransomware\/","title":{"rendered":"Azure introduced new Fusion Detection for Ransomware!"},"content":{"rendered":"\n<p>Hi Cloud Marathoners,<\/p>\n\n\n\n<p>This week a new service &#8211; Fusion Detection for Ransomware has been announced. These Fusion detections correlate alerts that are potentially associated with ransomware activities that are observed at defense evasion and execution stages during a specific timeframe.\u00a0<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What is Ransomware?  <\/h3>\n\n\n\n<p>Ransomware attack is a type of attack that involves using specific types of malicious software or malware to make a network or system inaccessible for the purpose of extortion \u2013 \u2018ransom\u2019. <\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"703\" height=\"497\" src=\"\/wp-content\/uploads\/2021\/08\/iStock-1022030450.jpg\" alt=\"\" class=\"wp-image-479\" srcset=\"\/wp-content\/uploads\/2021\/08\/iStock-1022030450.jpg 703w, \/wp-content\/uploads\/2021\/08\/iStock-1022030450-300x212.jpg 300w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/figure>\n\n\n\n<p>There is no doubt that ransomware attacks have taken a massive turn in being the top priority as a threat to many organizations. A\u00a0<a href=\"https:\/\/purplesec.us\/resources\/cyber-security-statistics\/ransomware\/#Cost\">recent report\u00a0released by\u00a0PurpleSec<\/a>\u00a0revealed that the estimated cost of ransomware attacks was $20 billion in 2020 and with downtime increasing by over 200% and the cost being 23x higher than 2019.<\/p>\n\n\n\n<p>Preventing such attacks in the first place would be the ideal solution but with the new trend of \u2018ransomware as a service\u2019 and human operated ransomware, the scope and the sophistication of attacks are increasing \u2013 attackers are using slow and stealth techniques to compromise network, which makes it harder to detect them in the first place.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">AI in action with Azure Sentinel for help!<\/h3>\n\n\n\n<p>Good new is that <a href=\"https:\/\/www.linkedin.com\/feed\/hashtag\/?keywords=azuresentinel&amp;highlightedUpdateUrns=urn%3Ali%3Aactivity%3A6830567721927753728\">#azuresentinel<\/a>\u00a0\ud83d\udd25 is constantly getting more efficient by introducing\u00a0<a href=\"https:\/\/www.linkedin.com\/feed\/hashtag\/?keywords=ai&amp;highlightedUpdateUrns=urn%3Ali%3Aactivity%3A6830567721927753728\">#AI<\/a>\u00a0in action &#8211; Sentinel\u00a0<a href=\"https:\/\/www.linkedin.com\/feed\/hashtag\/?keywords=fusion&amp;highlightedUpdateUrns=urn%3Ali%3Aactivity%3A6830567721927753728\">#fusion<\/a>!<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"478\" height=\"299\" src=\"\/wp-content\/uploads\/2021\/08\/Sylvie_Liu_3-1628273507782.png\" alt=\"\" class=\"wp-image-480\" srcset=\"\/wp-content\/uploads\/2021\/08\/Sylvie_Liu_3-1628273507782.png 478w, \/wp-content\/uploads\/2021\/08\/Sylvie_Liu_3-1628273507782-300x188.png 300w\" sizes=\"auto, (max-width: 478px) 85vw, 478px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>In order to help your analyst quickly understand the possible attack, Fusion provides you with a complete picture for the suspicious activities happened on the same device\/host by correlating signals from Microsoft products as well as signals in network and cloud. Supported data connectors include:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/sentinel\/connect-azure-security-center\">Azure Defender (Azure Security Center)<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/sentinel\/connect-microsoft-defender-advanced-threat-protection\">Microsoft Defender for Endpoint<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/sentinel\/connect-azure-atp\">Microsoft Defender for Identity<\/a><\/li><li><a rel=\"noreferrer noopener\" href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/sentinel\/connect-cloud-app-security\" target=\"_blank\">Microsoft Cloud App Security<\/a><\/li><li><a rel=\"noreferrer noopener\" href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/sentinel\/tutorial-detect-threats-built-in#scheduled\" target=\"_blank\">Azure Sentinel scheduled analytics rules<\/a>. <\/li><\/ul>\n\n\n\n<p>\u201dWith Fusion detection for ransomware that captures malicious activities at the defense evasion and execution stages of an attack, it gives security analysts an opportunity to quickly understand the suspicious activities happened around the same timeframe on the common entities, connect the dots and take immediate actions to disrupt the attack.\u201d<\/p>\n\n\n\n<p>Microsoft is commited to release new multistage attack scenarios detected by Fusion in Azure Sentinel. You could  keep an eye on there\u00a0<a rel=\"noreferrer noopener\" href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/sentinel\/fusion\" target=\"_blank\">Azure Sentinel Fusion<\/a>\u00a0page and get latest updates there \ud83d\ude42<\/p>\n\n\n\n<p>Stay tuned for more Azure automation &amp; Security related posts.<\/p>\n\n\n\n<p>F\u1d0f\u029f\u029f\u1d0f\u1d21 \u1d0d\u1d07 \ud83c\udfaf \u1d00\u0274\u1d05 become \u1d00&nbsp;<a href=\"https:\/\/www.linkedin.com\/feed\/hashtag\/?keywords=cloudmarathoner&amp;highlightedUpdateUrns=urn%3Ali%3Aactivity%3A6831288713784410112\">#cloudmarathoner<\/a>&nbsp;\u26c5\ud83c\udfc3\u200d\u2642\ufe0f\ud83c\udfc3\u200d\u2640\ufe0f &#8211; \ud835\udc0b\ud835\udc04\ud835\udc13&#8217;\ud835\udc12 \ud835\udc02\ud835\udc0e\ud835\udc0d\ud835\udc0d\ud835\udc04\ud835\udc02\ud835\udc13 \ud83d\udc4d<\/p>\n\n\n\n<p><a href=\"https:\/\/www.linkedin.com\/feed\/hashtag\/?keywords=microsoftsecurity&amp;highlightedUpdateUrns=urn%3Ali%3Aactivity%3A6830567721927753728\">#microsoftsecurity<\/a> <br><a href=\"https:\/\/www.linkedin.com\/feed\/hashtag\/?keywords=security&amp;highlightedUpdateUrns=urn%3Ali%3Aactivity%3A6830567721927753728\">#security<\/a><br><a href=\"https:\/\/www.linkedin.com\/feed\/hashtag\/?keywords=infosec&amp;highlightedUpdateUrns=urn%3Ali%3Aactivity%3A6830567721927753728\">#infosec<\/a><br><a href=\"https:\/\/www.linkedin.com\/feed\/hashtag\/?keywords=cybersecurity&amp;highlightedUpdateUrns=urn%3Ali%3Aactivity%3A6830567721927753728\">#cybersecurity<\/a><\/p>\n<div class=\"pvc_clear\"><\/div><p id=\"pvc_stats_478\" class=\"pvc_stats all  \" data-element-id=\"478\" style=\"\"><i class=\"pvc-stats-icon medium\" aria-hidden=\"true\"><svg aria-hidden=\"true\" focusable=\"false\" data-prefix=\"far\" data-icon=\"chart-bar\" role=\"img\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" viewBox=\"0 0 512 512\" class=\"svg-inline--fa fa-chart-bar fa-w-16 fa-2x\"><path fill=\"currentColor\" d=\"M396.8 352h22.4c6.4 0 12.8-6.4 12.8-12.8V108.8c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v230.4c0 6.4 6.4 12.8 12.8 12.8zm-192 0h22.4c6.4 0 12.8-6.4 12.8-12.8V140.8c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v198.4c0 6.4 6.4 12.8 12.8 12.8zm96 0h22.4c6.4 0 12.8-6.4 12.8-12.8V204.8c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v134.4c0 6.4 6.4 12.8 12.8 12.8zM496 400H48V80c0-8.84-7.16-16-16-16H16C7.16 64 0 71.16 0 80v336c0 17.67 14.33 32 32 32h464c8.84 0 16-7.16 16-16v-16c0-8.84-7.16-16-16-16zm-387.2-48h22.4c6.4 0 12.8-6.4 12.8-12.8v-70.4c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v70.4c0 6.4 6.4 12.8 12.8 12.8z\" class=\"\"><\/path><\/svg><\/i> <img loading=\"lazy\" decoding=\"async\" width=\"16\" height=\"16\" alt=\"Loading\" src=\"\/wp-content\/plugins\/page-views-count\/ajax-loader-2x.gif\" border=0 \/><\/p><div class=\"pvc_clear\"><\/div>","protected":false},"excerpt":{"rendered":"<p>Hi Cloud Marathoners, This week a new service &#8211; Fusion Detection for Ransomware has been announced. These Fusion detections correlate alerts that are potentially associated with ransomware activities that are observed at defense evasion and execution stages during a specific timeframe.\u00a0 What is Ransomware? Ransomware attack is a type of attack that involves using specific &hellip; <a href=\"https:\/\/www.thecloudmarathoner.com\/index.php\/2021\/08\/12\/azure-introduced-new-fusion-detection-for-ransomware\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Azure introduced new Fusion Detection for Ransomware!&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[24,18,15],"tags":[],"class_list":["post-478","post","type-post","status-publish","format-standard","hentry","category-azure-sentinel","category-azure","category-security-governance"],"_links":{"self":[{"href":"https:\/\/www.thecloudmarathoner.com\/index.php\/wp-json\/wp\/v2\/posts\/478","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thecloudmarathoner.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thecloudmarathoner.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thecloudmarathoner.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thecloudmarathoner.com\/index.php\/wp-json\/wp\/v2\/comments?post=478"}],"version-history":[{"count":3,"href":"https:\/\/www.thecloudmarathoner.com\/index.php\/wp-json\/wp\/v2\/posts\/478\/revisions"}],"predecessor-version":[{"id":483,"href":"https:\/\/www.thecloudmarathoner.com\/index.php\/wp-json\/wp\/v2\/posts\/478\/revisions\/483"}],"wp:attachment":[{"href":"https:\/\/www.thecloudmarathoner.com\/index.php\/wp-json\/wp\/v2\/media?parent=478"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thecloudmarathoner.com\/index.php\/wp-json\/wp\/v2\/categories?post=478"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thecloudmarathoner.com\/index.php\/wp-json\/wp\/v2\/tags?post=478"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}