Matt McSpiritHost
So let me walk you through a multi-stage attack across a containerized environment to show you this in action from the perspective of a SOC analyst.

I'm in Microsoft Defender in the Incidents view, Filter to Container-Related Incidents, and I can see four related containers.

And notice this is already correlated into a single incident, not multiple alerts.

You can see it's flagged as high impact with a critical asset label and the crown icon in the incident graph showing asset criticality.

On the left is the attack story with alerts listed in chronological order, color coded by severity.

If we go back to the incident graph, container resources are in black and related identities and services are in white.

In this case, Defender has detected 19 alerts for this incident in near real time and stitched them into a single timeline.

Here we can see the initial access signal was from a Kubernetes API request from a proxy IP address.

Identity compromise and escalation then occurred with credentials accessed from a service principle.

And finally, Defender for Cloud's cross-cloud correlation surfaces lateral movements spanning environments, revealing a brute force attack originating from an exposed Azure Kubernetes cluster targeting an AWS relational database service resource.

And if we ungroup similar nodes, we see a user indicated by another blue icon and we can pivot directly into the attack path view.

This is where we connect runtime activity back to security posture and exposure.

It's concluded that the container is internet exposed with high severity vulnerabilities and it's using a managed identity to access a protected storage account.

So let me walk you through a multi-stage attack across a containerized environment to show you this in action from the perspective of a SOC analyst.

I'm in Microsoft Defender in the Incidents view, Filter to Container-Related Incidents, and I can see four related containers.

And notice this is already correlated into a single incident, not multiple alerts.

You can see it's flagged as high impact with a critical asset label and the crown icon in the incident graph showing asset criticality.

On the left is the attack story with alerts listed in chronological order, color coded by severity.

If we go back to the incident graph, container resources are in black and related identities and services are in white.

In this case, Defender has detected 19 alerts for this incident in near real time and stitched them into a single timeline.

Here we can see the initial access signal was from a Kubernetes API request from a proxy IP address.

Identity compromise and escalation then occurred with credentials accessed from a service principle.

And finally, Defender for Cloud's cross-cloud correlation surfaces lateral movements spanning environments, revealing a brute force attack originating from an exposed Azure Kubernetes cluster targeting an AWS relational database service resource.

And if we ungroup similar nodes, we see a user indicated by another blue icon and we can pivot directly into the attack path view.

This is where we connect runtime activity back to security posture and exposure.

It's concluded that the container is internet exposed with high severity vulnerabilities and it's using a managed identity to access a protected storage account.
The rest of this transcript — segmented and speaker-labeled, so you land on the exact moment something was said
Search every transcript — by keyword, by phrase, or by meaning, across every show Radar indexes
Trends — what is surging across podcasts, measured against its own baseline
Alerts — when a name you follow appears in a newly indexed episode
No account is needed to search Radar.