128 Seconds to disruption: Microsoft Defender stops ransomware at QNET
In this article What is device isolation? Case study: QNET Attack chain overview MITRE ATT&CK techniques observed References Learn more Microsoft Defender’s attack disruption now includes device isolation, a new response action that extends autonomous protection directly to compromised endpoints. At QNET, an attacker initiated a multi-stage attack using a legitimate Windows tool on a compromised endpoint to retrieve a malicious remote payload–a classic living-off-the-land (LOL) technique that often evades traditional containment. By automatically enforcing the new device isolation action on the compromised endpoint, Defender attack disruption stopped the attack dead in its tracks. From the first high-severity alert to completed isolation, after only 128 seconds, Defender cut off the attack chain before the second-stage payload could establish persistence or move beyond the host. The growing threat: when the endpoint is the blast radius Attack disruption has proven highly effective at stopping multistage, cross-domain attacks by disrupting the attacker’s ability to move across the environment. In many identity-driven attack scenarios, containing the compromised user is enough to shut down the attack chain, preventing lateral movement and limiting the attacker’s ability to access additional systems, identities, and resources. However, we are increasingly seeing a different class of high-severity incidents that begin with initial access directly on the device. Once adversaries establish a foothold on an endpoint, they can plant multiple persistence mechanisms and continue operating locally on the machine. This means that acting against the user’s identity alone is no longer enough to dismantle the threat. In these scenarios, the attacker has multiple ways to communicate and operate on the device beyond the user entity; the malicious code is already executing locally on the machine. The attacker doesn’t have to move laterally immediately; they can establish persistence, steal credentials, inject into processes, and prepare follow-on stages directly from the compromised endpoint itself. Previously, stopping these attacks required manual triage and response, giving attackers time to advance. Device isolation closes this gap by automatically correlating signals, assessing the threat, and isolating the compromised device within seconds. Traditional response approaches often depend on static playbooks triggered by individual alerts and maintained through manual tuning. Attack disruption instead uses AI-driven correlation and real-time analysis to identify multi-stage attacks by connecting signals across the environment before taking action. Device isolation is enforced only when the disruption pipeline reaches a high-confidence verdict—a threshold maintained at 99% precision. What is device isolation? When Microsoft Defender determines with high confidence that an endpoint is compromised, it isolates the device to immediately stop attacker activity and reduce the risk of further impact, such as data exfiltration and lateral movement. What happens during device Isolation When a device is isolated, all external network connectivity is blocked while maintaining access to required security services like Microsoft Defender for Endpoint. Selective isolation is supported, allowing customer-defined services or exclusions to continue functioning. Automatic device isolation is scoped to the affected device (supported today on onboarded MDE workstations), time-limited, and operator-controlled. Security teams can review context, take follow-up actions, and manually release isolation when it’s safe to do so. Why it matters Device isolation is a powerful containment control because it disrupts the attack regardless of how the device was compromised or what the attacker planned to do next. A single action cuts off network access, breaking lateral movement, command and control, credential theft, and rapid encryption–effectively stopping hands-on activ…
AI Analysis
Technical Summary
Microsoft Defender's device isolation is an autonomous response action that isolates compromised endpoints to disrupt ransomware and other multi-stage attacks. The feature uses AI-driven correlation and real-time analysis to identify high-confidence compromises and isolate the device within seconds, blocking external network access but maintaining security service connectivity. A case study at QNET demonstrated that Defender stopped a ransomware attack in 128 seconds by isolating the compromised endpoint before the attacker could establish persistence or move laterally. Device isolation is scoped to the affected device, time-limited, operator-controlled, and supports selective network exclusions. This approach addresses threats that operate locally on endpoints beyond user identity compromise, preventing credential theft, lateral movement, command and control, and rapid encryption.
Potential Impact
The device isolation feature effectively stops attacker activity on compromised endpoints by cutting off network access, thereby preventing lateral movement, credential theft, command and control communication, and ransomware encryption. This reduces the blast radius of endpoint compromises and limits attacker persistence and follow-on stages. The rapid automated response shortens the window attackers have to advance their attacks, improving overall security posture against endpoint-based threats.
Mitigation Recommendations
Microsoft Defender's device isolation feature provides an automated, AI-driven containment control that isolates compromised devices at a high-confidence threshold, effectively stopping attacks without manual intervention. Security teams should ensure Microsoft Defender for Endpoint is deployed and device isolation is enabled and properly configured. Since this is a built-in feature of Microsoft Defender, no additional patching is required. Operators can review isolation context and manually release devices when safe. No further immediate action is required beyond enabling and monitoring this capability.
128 Seconds to disruption: Microsoft Defender stops ransomware at QNET
Description
In this article What is device isolation? Case study: QNET Attack chain overview MITRE ATT&CK techniques observed References Learn more Microsoft Defender’s attack disruption now includes device isolation, a new response action that extends autonomous protection directly to compromised endpoints. At QNET, an attacker initiated a multi-stage attack using a legitimate Windows tool on a compromised endpoint to retrieve a malicious remote payload–a classic living-off-the-land (LOL) technique that often evades traditional containment. By automatically enforcing the new device isolation action on the compromised endpoint, Defender attack disruption stopped the attack dead in its tracks. From the first high-severity alert to completed isolation, after only 128 seconds, Defender cut off the attack chain before the second-stage payload could establish persistence or move beyond the host. The growing threat: when the endpoint is the blast radius Attack disruption has proven highly effective at stopping multistage, cross-domain attacks by disrupting the attacker’s ability to move across the environment. In many identity-driven attack scenarios, containing the compromised user is enough to shut down the attack chain, preventing lateral movement and limiting the attacker’s ability to access additional systems, identities, and resources. However, we are increasingly seeing a different class of high-severity incidents that begin with initial access directly on the device. Once adversaries establish a foothold on an endpoint, they can plant multiple persistence mechanisms and continue operating locally on the machine. This means that acting against the user’s identity alone is no longer enough to dismantle the threat. In these scenarios, the attacker has multiple ways to communicate and operate on the device beyond the user entity; the malicious code is already executing locally on the machine. The attacker doesn’t have to move laterally immediately; they can establish persistence, steal credentials, inject into processes, and prepare follow-on stages directly from the compromised endpoint itself. Previously, stopping these attacks required manual triage and response, giving attackers time to advance. Device isolation closes this gap by automatically correlating signals, assessing the threat, and isolating the compromised device within seconds. Traditional response approaches often depend on static playbooks triggered by individual alerts and maintained through manual tuning. Attack disruption instead uses AI-driven correlation and real-time analysis to identify multi-stage attacks by connecting signals across the environment before taking action. Device isolation is enforced only when the disruption pipeline reaches a high-confidence verdict—a threshold maintained at 99% precision. What is device isolation? When Microsoft Defender determines with high confidence that an endpoint is compromised, it isolates the device to immediately stop attacker activity and reduce the risk of further impact, such as data exfiltration and lateral movement. What happens during device Isolation When a device is isolated, all external network connectivity is blocked while maintaining access to required security services like Microsoft Defender for Endpoint. Selective isolation is supported, allowing customer-defined services or exclusions to continue functioning. Automatic device isolation is scoped to the affected device (supported today on onboarded MDE workstations), time-limited, and operator-controlled. Security teams can review context, take follow-up actions, and manually release isolation when it’s safe to do so. Why it matters Device isolation is a powerful containment control because it disrupts the attack regardless of how the device was compromised or what the attacker planned to do next. A single action cuts off network access, breaking lateral movement, command and control, credential theft, and rapid encryption–effectively stopping hands-on activ…
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Microsoft Defender's device isolation is an autonomous response action that isolates compromised endpoints to disrupt ransomware and other multi-stage attacks. The feature uses AI-driven correlation and real-time analysis to identify high-confidence compromises and isolate the device within seconds, blocking external network access but maintaining security service connectivity. A case study at QNET demonstrated that Defender stopped a ransomware attack in 128 seconds by isolating the compromised endpoint before the attacker could establish persistence or move laterally. Device isolation is scoped to the affected device, time-limited, operator-controlled, and supports selective network exclusions. This approach addresses threats that operate locally on endpoints beyond user identity compromise, preventing credential theft, lateral movement, command and control, and rapid encryption.
Potential Impact
The device isolation feature effectively stops attacker activity on compromised endpoints by cutting off network access, thereby preventing lateral movement, credential theft, command and control communication, and ransomware encryption. This reduces the blast radius of endpoint compromises and limits attacker persistence and follow-on stages. The rapid automated response shortens the window attackers have to advance their attacks, improving overall security posture against endpoint-based threats.
Defensive Guidance
Microsoft Defender's device isolation feature provides an automated, AI-driven containment control that isolates compromised devices at a high-confidence threshold, effectively stopping attacks without manual intervention. Security teams should ensure Microsoft Defender for Endpoint is deployed and device isolation is enabled and properly configured. Since this is a built-in feature of Microsoft Defender, no additional patching is required. Operators can review isolation context and manually release devices when safe. No further immediate action is required beyond enabling and monitoring this capability.
Technical Details
- Classification
- {"confidence":0.82,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.microsoft.com/en-us/security/blog/2026/08/04/129-seconds-disruption-microsoft-defender-stops-ransomware-qnet/","fetched":true,"fetchedAt":"2026-08-05T18:39:32.172Z","wordCount":2294}
Threat ID: 6a738364bf8831d53948dfae
Added to database: 08/05/2026, 18:39:32 UTC
Last enriched: 08/05/2026, 18:40:48 UTC
Last updated: 09/18/2026, 02:29:48 UTC
Views: 143
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.