Hi everyone. I’ve been reading here for a while but this is my first post. I work in HRIS, so endpoint security isn’t my primary area, but I’ve been involved in our recent security evaluations.
We just ran a simulated ransomware attack in our test environment, using Defender for Endpoint as our main protection. I wanted to share the outcome because it was... mixed.
The simulation involved a user downloading a disguised payload. Defender’s behavioral blocking and attack surface reduction rules didn’t trigger on initial execution. The encryption process started on several test files before Defender finally flagged and contained the activity. By that point, the damage in a real scenario would have been significant.
My understanding is that it’s supposed to catch these things earlier. Has anyone else run similar tests? I’m trying to figure out if this is a configuration issue on our end, or if we need to adjust our expectations. We’re reviewing the timeline in the security center now, but I’m curious about real-world experiences, especially from teams that handle sensitive employee data like we do.