{"id":20427,"date":"2025-10-06T18:43:58","date_gmt":"2025-10-06T18:43:58","guid":{"rendered":"http:\/\/localhost\/?p=20427"},"modified":"2025-10-06T18:43:58","modified_gmt":"2025-10-06T18:43:58","slug":"inside-microsoft-threat-intelligence-calm-in-the-chaos","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=20427","title":{"rendered":"Inside Microsoft Threat Intelligence: Calm in the chaos_MSSECURE:492A55382A802CEF3ABDCD78B735B70B"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2025-10-06T22:45:06&#8243;,&#8221;description&#8221;:&#8221;## Leading Through the Worst Day\\n\\nIncident response is never orderly. Threat actors don\u2019t wait. Environments are compromised. Data is missing. Confidence is shaken. But for Microsoft\u2019s Incident Response (IR) team, that chaos is exactly where the work begins.\\n\\nIn Episode 1, we showed how Microsoft Threat Intelligence and the Digital Crime Unit (DCU) disrupted Storm-1152\u2019s massive fake account operation, turning threat intelligence into global action. In this second chapter of _Inside Microsoft Threat Intelligence_ , we move from disruption to response, showing what happens when defenders face the worst day in security, and how calm leadership transforms outcomes.\\n\\nAdrian Hill, lead investigator for Microsoft IR, explains it simply: \u201cOur job is to bring clarity, calm, and momentum\u2014fast. We set the tone in the first 30 seconds. Because if the customer doesn\u2019t trust us immediately, we can\u2019t help them recover.\u201d\\n\\nWhether dropped into an active breach or brought in for proactive support, Microsoft\u2019s IR team works to stabilize, guide, and rebuild. Every engagement starts with empathy and ends with action.\\n\\n## Putting the customer first\\n\\nIn high-stakes incidents, Microsoft Incident Response isn\u2019t always the only team on site. Adrian often finds himself shoulder to shoulder with other vendors and internal stakeholders. But rather than compete, he leads with clarity and collaboration, and ensure all parties are marching toward the same goal.\\n\\nIn one recent case, Microsoft joined mid-incident while a threat actor still had active control of the environment. The customer wasn\u2019t even aware Microsoft\u2019s IR team was on deck. Within 30 minutes, Adrian\u2019s team had surfaced threat intelligence from Defender and other telemetry sources that no one else had uncovered. It wasn\u2019t just a faster response. It changed the customer\u2019s perception of what Microsoft Incident Response could deliver.\\n\\n## Turning chaos into ecosystem protection\\n\\nMicrosoft\u2019s IR team doesn\u2019t just clean up attacks; they feed intelligence back into the ecosystem. Every novel tactic, unusual behavior, or new artifact discovered during a customer engagement gets routed back to Microsoft Threat Intelligence. That insight becomes new detections, improved playbooks, and protections that safeguard millions of users and organizations worldwide.\\n\\nThis loop, from the field to Microsoft Threat Intelligence to product integration, is what makes our end-to-end security story unique. Incident response isn\u2019t the last line of defense. It\u2019s the front line of innovation.\\n\\n## From recovery to partnership\\n\\nIR is rarely one-and-done. In the same engagement, Adrian\u2019s team helped recover cloud backups, secure infrastructure, and walk the customer through containment and long-term strategy. Months later, the organization came back for further briefings, roadmap work, and proactive guidance.\\n\\nThat follow-through is what builds trust and transforms perception.\\n\\n\u201cWe don\u2019t show up to pitch Microsoft,\u201d Adrian says. \u201cWe show up to help people. And that\u2019s what makes them want to keep working with us.\u201d\\n\\nMicrosoft\u2019s incident response isn\u2019t just about stopping attacks. It\u2019s about restoring confidence and helping customers take control of their security future and building resilience.\\n\\nMissed episode one of Inside Microsoft Threat Intelligence? Catch it here.\\n\\nWatch the video\\n\\nThe post Inside Microsoft Threat Intelligence: Calm in the chaos appeared first on Microsoft Security Blog.&#8221;,&#8221;published&#8221;:&#8221;2025-10-06T21:00:00&#8243;,&#8221;modified&#8221;:&#8221;2025-10-06T21:00:00&#8243;,&#8221;type&#8221;:&#8221;mssecure&#8221;,&#8221;title&#8221;:&#8221;Inside Microsoft Threat Intelligence: Calm in the chaos&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;MSSECURE:492A55382A802CEF3ABDCD78B735B70B&#8221;,&#8221;bulletinFamily&#8221;:&#8221;blog&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[],&#8221;sourceData&#8221;:&#8221;&#8221;,&#8221;sourceHref&#8221;:&#8221;&#8221;,&#8221;cvss&#8221;:{&#8220;score&#8221;:0,&#8221;severity&#8221;:&#8221;NONE&#8221;,&#8221;vector&#8221;:&#8221;NONE&#8221;,&#8221;version&#8221;:&#8221;NONE&#8221;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/www.microsoft.com\/en-us\/security\/security-insider\/threat-landscape\/inside-microsoft-threat-intelligence-calm-in-chaos#overview-video&#8221;,&#8221;category_name&#8221;:&#8221;News&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2025-10-06T22:45:06&#8243;,&#8221;description&#8221;:&#8221;## Leading Through the Worst Day\\n\\nIncident response is never orderly. Threat actors don\u2019t wait. Environments are compromised. Data is missing. Confidence is shaken. But for&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[6,8,12,110,13,33,7,11,5],"class_list":["post-20427","post","type-post","status-publish","format-standard","hentry","category-category_news","tag-cve","tag-cvss","tag-exploit","tag-mssecure","tag-news","tag-none","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Inside Microsoft Threat Intelligence: Calm in the chaos_MSSECURE:492A55382A802CEF3ABDCD78B735B70B - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=20427\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Inside Microsoft Threat Intelligence: Calm in the chaos_MSSECURE:492A55382A802CEF3ABDCD78B735B70B - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2025-10-06T22:45:06&#8243;,&#8221;description&#8221;:&#8221;## Leading Through the Worst DaynnIncident response is never orderly. Threat actors don\u2019t wait. Environments are compromised. Data is missing. Confidence is shaken. But for...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=20427\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2025-10-06T18:43:58+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=20427#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=20427\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"Inside Microsoft Threat Intelligence: Calm in the chaos_MSSECURE:492A55382A802CEF3ABDCD78B735B70B\",\"datePublished\":\"2025-10-06T18:43:58+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=20427\"},\"wordCount\":675,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"exploit\",\"mssecure\",\"news\",\"NONE\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_news\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=20427#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=20427\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=20427\",\"name\":\"Inside Microsoft Threat Intelligence: Calm in the chaos_MSSECURE:492A55382A802CEF3ABDCD78B735B70B - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2025-10-06T18:43:58+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=20427#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=20427\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=20427#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Inside Microsoft Threat Intelligence: Calm in the chaos_MSSECURE:492A55382A802CEF3ABDCD78B735B70B\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Inside Microsoft Threat Intelligence: Calm in the chaos_MSSECURE:492A55382A802CEF3ABDCD78B735B70B - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=20427","og_locale":"en_US","og_type":"article","og_title":"Inside Microsoft Threat Intelligence: Calm in the chaos_MSSECURE:492A55382A802CEF3ABDCD78B735B70B - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2025-10-06T22:45:06&#8243;,&#8221;description&#8221;:&#8221;## Leading Through the Worst DaynnIncident response is never orderly. Threat actors don\u2019t wait. Environments are compromised. Data is missing. Confidence is shaken. But for...","og_url":"https:\/\/zero.redgem.net\/?p=20427","og_site_name":"zero redgem","article_published_time":"2025-10-06T18:43:58+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=20427#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=20427"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"Inside Microsoft Threat Intelligence: Calm in the chaos_MSSECURE:492A55382A802CEF3ABDCD78B735B70B","datePublished":"2025-10-06T18:43:58+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=20427"},"wordCount":675,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","exploit","mssecure","news","NONE","Security","tapic","Vulnerability"],"articleSection":["category_news"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=20427#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=20427","url":"https:\/\/zero.redgem.net\/?p=20427","name":"Inside Microsoft Threat Intelligence: Calm in the chaos_MSSECURE:492A55382A802CEF3ABDCD78B735B70B - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2025-10-06T18:43:58+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=20427#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=20427"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=20427#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"Inside Microsoft Threat Intelligence: Calm in the chaos_MSSECURE:492A55382A802CEF3ABDCD78B735B70B"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/20427","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=20427"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/20427\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=20427"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=20427"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=20427"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}