This is the Trace Id: fbe1f5c96753d23e022d113364cce7b8
Skip to main content Microsoft 365 Office Azure Copilot Windows XBOX Support Windows Apps OneDrive Outlook Moving from Skype to Teams OneNote Microsoft Teams Shop XBOX Accessories XBOX games Microsoft AI Microsoft Security Azure Dynamics 365 Microsoft 365 for business Microsoft Power Platform Windows 365 Digital Sovereignty Microsoft Developer Microsoft Learn Support for AI marketplace apps Microsoft Tech Community Microsoft Marketplace Software companies Visual Studio Free downloads & security Education Gift cards Licensing View Sitemap

Windows Defender Advanced Threat Protection - Ransomware response playbook

This playbook discusses how enterprises can leverage Windows Defender ATP to detect, investigate, and mitigate ransomware threats in their networks.

Important! Selecting a language below will dynamically change the complete page content to that language.

Download
  • Version:

    1.0

    Date Published:

    7/15/2024

    File Name:

    Windows Defender ATP - Ransomware response playbook.pdf

    File Size:

    1.7 MB

    This document provides an overview of how enterprise customers can leverage Windows Defender Advanced Threat Protection (Windows Defender ATP) to detect, investigate, and mitigate ransomware threats in their networks. It walks through different stages of incident response and shows how Windows Defender ATP can serve as an invaluable tool during each of these stages. This playbook refers to a real-world infection involving Cerber ransomware, one of the most active ransomware families. It shows how Windows Defender ATP can help catch a specific Cerber variant and, at the same time, catch ransomware behavior generically.
  • Supported Operating Systems

    Windows 10

    Use a web browser or a PDF reader to view this document.
  • No special instructions required.