Case study: How predictive shielding in Defender stopped GPO-based ransomware before it started
2026-03-24T08:52:20Z•8b7e59959fe4e4ee73e379fba58f4cdcd8906adafa2fa19bdbd18d5b762cbb10
AI securityCTI-REALMGPOIOCsMicrosoft DefenderMicrosoft PurviewSEO poisoningStorm-2561Zero Trust for AIagentic AIcredential theftdetection engineeringemail securitygroup policymitigationobservabilityphishingpredictive shieldingransomwaresocial engineeringvoice phishing
What happened
Collection of Microsoft Security Blog posts covering: a case study where Microsoft Defender’s predictive shielding blocked a human-operated, GPO-based ransomware campaign—hardening ~700 devices and preventing any GPO-based encryptions; CTI-REALM, an open-source benchmark for using AI agents to convert CTI into validated detection rules; new guidance and tooling for securing agentic AI and a Zero Trust for AI pillar; observability guidance for AI systems; Microsoft Purview governance updates for Fabric; a DART analysis of a Teams voice-phishing compromise; Storm-2561 SEO-poisoning campaign that
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 8b7e59959fe4e4ee73e379fba58f4cdcd8906adafa2fa19bdbd18d5b762cbb10
- Enrichment time
- 2026-03-24T08:52:20Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.