Microsoft Defender for Cloud
Cloud and workloads

Identify and remediate attack paths in Microsoft Defender for Cloud

In brief

The page now uses revised wording for attack-path analysis, clarifies CSPM, agentless scanning, and container setup prerequisites, and streamlines investigation and remediation steps. It also adds a stable anchor for the remediation section.

What Defender admins need to know

Administrators have clearer guidance for preparing environments, viewing container-related attack paths, and remediating recommendations.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Identify and remediate attack paths in Microsoft Defender for Cloud

Defender for Cloud uses a proprietary algorithm to locate potential attack paths specific toin your multicloud environment. Defender for CloudIt focuses on real, externally driven and exploitableexternal threats rather thanthat attackers can exploit, not broad scenarios. The algorithm detectsfinds attack paths that beginstart outside your organization and progresslead to business-critical targets, helpingtargets. This helps you cut through the noise and act faster.

You can use attack path analysis to addressfind and fix the security issues that pose immediate threats and have the greatest potential for exploitation in your environment.biggest risk. Defender for Cloud analyzesshows which security issues are part of externally exposed attack paths that attackers could use to breach your environment. ItDefender for Cloud also highlights the security recommendations you need to resolve to mitigate these issues.resolve.

By defaultdefault, attack paths are organizedsorted by risk level. TheA risk level is determined by a context-aware risk-prioritization engine that considersreviews the risk factors of each resource. Learn more aboutresource to set its priority. For details on how Defender for Cloud ranks recommendations, see Risk prioritization.

Prerequisites

Before you begin, make sure your environment meets these requirements:

To view attack paths related to containers:

To see container-related attack paths, complete one of the following setup options: - Enable agentless container posture extension in Defender CSPM.

  • - Enable Defender for Containers and install the relevant agents to view attack paths related to containers.agents. This option also giveslets you the ability to query container data plane workloads in cloud security explorer container data plane workloads in security explorer.
  • .
    • Required roles and permissions: Security Reader, Security Admin, Reader, Contributor, or Owner.

    1. Select a recommendation.

    2. Remediate the recommendation.

      Once you're done with your investigation of an attack path and you review all of the associated findings and recommendations, you can start to remediate the attack path.

    3. Remediate the recommendation.

    Once an attack path is resolved, it can take up to 24 hours for an attack path to be removed from the list.

    Remediate attack paths

    OnceAfter you're done with your investigation of investigate an attack path and you review all of the associatedits findings and recommendations, you can start to remediate the attack path.fix it.

    To remediate an attack path in the Azure portal:

    ::: zone-end

    Remediate all recommendations withinfor an attack path

    Attack path analysis grantslets you the ability to see all recommendations byfor an attack path without havingin one place. You don't need to check each node individually. You can resolve all recommendations without having to view each node individually.one by one.

    The remediation path containsThere are two types of recommendation:recommendations:

    • Recommendations - RecommendationsSteps that mitigatefix the attack path.
    • Additional recommendations - RecommendationsSteps that reduce exploitation risks,lower risk but don't mitigatefully fix the attack path.

    ::: zone pivot="azure-portal"


    Next stepsteps

    [!div class="nextstepaction"] Build queries with cloud security explorer