Patch me if you can: Cyberattack Series
The Microsoft Incident Response team takes swift action to help contain a ransomware attack and regain positive administrative control of the customer environment.
Microsoft Antimalware for Azure Cloud Services and Virtual Machines is now generally available for Microsoft Azure customers. This new security extension for Microsoft Azure provides an additional layer of security by helping to identify, block and remove malicious software on virtual machines managed by Azure customers. It provides real time protection from the latest threats, can perform on-demand scanning, and monitoring at no additional charge to Microsoft Azure customers. Customers can select the Microsoft Antimalware security extension when creating a virtual machine and configure the service programmatically for virtual machines and cloud services using APIs/PowerShell.
Antimalware events are logged to the customer’s Azure Storage account when configured with Azure Diagnostics and can be piped to HDInsight or an SIEM for further analysis. More information is available in the Microsoft Antimalware Whitepaper.