Erick Cisneros
ContactResume
Directory
Overview
Experience
Investigations & Tooling
The Trophy Case
Education
Contact Me
Direct Inquiries
Back to Security Investigations & Tooling
INC-2025-VD01

Virus Detection & Device Isolation

STATUS: RESOLVED / LAB

ANALYST: Erick Cisneros Ruballos

DATETIME: Nov 15, 2024

A technical demonstration of incident response procedures utilizing Microsoft Defender for Endpoint to halt lateral movement by completely isolating a compromised host off the network while pulling forensic telemetry.

Incident ResponseMDEKQLForensicsLive Response
See Full Report on GitHub
Case Brief

Executive Summary

During a routine lab operation, a malicious payload was detected and executed on a Windows 10 virtual machine segment. Microsoft Defender for Endpoint successfully caught the Antivirus event, triggering standard containment protocols.

The device was rapidly isolated from the network to prevent lateral movement. A full forensic investigation package was pulled remotely, allowing for safe telemetry analysis. Once the artifact was remediated, the device was released back into the network, demonstrating a complete end-to-end incident response lifecycle.

CLASSIFICATIONMALWARE
TARGET ASSETWin10-VM
ORIGIN GEOLab Environment
COMPROMISED ADN/A
Containment Lifecycle

Response Timeline

STAGE 1

Query & Detection

Initiating the response playbook requires solidifying the scope of the virus alert. We executed an advanced hunting query to directly poll DeviceEvents specifically for internal Windows Defender AV alarms.

Detection Results in Defender
STAGE 2

Enforce Isolation

With malicious activity confirmed, immediate containment is critical. Isolation severs the host's ability to speak to the internet, domain controllers, and local subnets—restricting communications solely to the Microsoft Defender sensor heartbeat.

Isolation Action in MDE
STAGE 3

Forensic Package Acquisition

While the host is isolated, we utilize MDE's remote response capabilities to pull a full Investigation Package. This zip archive contains crucial volatile data including Autorun keys, Active Network Connections, Process trees, and Security Event Logs over the last 30 days.

Requesting Package
Package Contents
STAGE 4

Network Verification

Before isolation, host traffic succeeded (8.8.8.8 responses). Post isolation, host traffic was natively dropped by the Windows filtering platform, proving network severance.

Ping Before
Ping After
STAGE 5

Remediation & Release

Following the extraction of evidence and remediation of the malicious artifacts, the machine was declared clean. A release command was executed, reconnecting the VM.

Release from Isolation
Threat Intelligence

Indicators of Compromise (IOCs)

Network Infrastructure
Connection StateIsolated (WFP Dropped)
Sensor HeartbeatMaintained (Port 443)
Filesystem & Payloads
Forensic ArchiveInvestigationPackage.zip
Trigger EventAntivirusDetection
Telemetry Reconstruction

KQL Threat Hunt Validation

Real-time Antivirus Detection Polling
KQL Query
DeviceEvents
| where ActionType == "AntivirusDetection"
| project Timestamp, DeviceId, DeviceName, FileName, FolderPath
| sort by Timestamp desc

Strategic Recommendations

  • 1Ensure all lab endpoints have the Microsoft Defender for Endpoint sensor fully deployed.
  • 2Implement Automated Investigation & Response (AIR) capability in MDE to drastically reduce time-to-containment for Antivirus events.
  • 3Utilize Live Response shells iteratively to search memory and active processes before returning complex endpoints to the general network.
© 2026 Erick Cisneros Ruballos
LinkedIn•GitHub•Direct Email