{"id":61223,"date":"2026-08-04T17:54:04","date_gmt":"2026-08-04T17:54:04","guid":{"rendered":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/?p=148812"},"modified":"2026-08-04T17:54:04","modified_gmt":"2026-08-04T17:54:04","slug":"128-seconds-to-disruption-microsoft-defender-stops-ransomware-at-qnet","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/128-seconds-to-disruption-microsoft-defender-stops-ransomware-at-qnet\/","title":{"rendered":"128 Seconds to disruption: Microsoft Defender stops ransomware at QNET\u00a0"},"content":{"rendered":"<aside class=\"table-of-contents-block accordion wp-block-bloginabox-theme-table-of-contents\" id=\"accordion-584ea111-0135-4799-8110-a2f85028f6e6\" data-bi-an=\"table-of-contents\"> <button class=\"btn btn-collapse\" type=\"button\" aria-expanded=\"true\" aria-controls=\"accordion-collapse-584ea111-0135-4799-8110-a2f85028f6e6\"> <span class=\"table-of-contents-block__label\">In this article<\/span> <span class=\"table-of-contents-block__current\" aria-hidden=\"true\"><\/span> <svg class=\"table-of-contents-block__arrow\" aria-label=\"Toggle arrow\" width=\"18\" height=\"11\" viewBox=\"0 0 18 11\" fill=\"none\"> <path d=\"M15.7761 11L18 8.82043L9 0L0 8.82043L2.22394 11L9 4.35913L15.7761 11Z\" fill=\"currentColor\" \/> <\/svg> <\/button> <span class=\"table-of-contents-block__progress-bar\"><\/span><br \/>\n<\/aside>\n<p class=\"wp-block-paragraph\">Microsoft Defender\u2019s attack disruption now includes device isolation, a new response action that extends autonomous protection directly to compromised endpoints.<\/p>\n<p class=\"wp-block-paragraph\">At QNET, an attacker initiated a multi-stage attack using a legitimate Windows tool on a compromised endpoint to retrieve a malicious remote payload\u2013a classic living-off-the-land (LOL) technique that often evades traditional containment. By automatically enforcing the&nbsp;new device isolation action&nbsp;on the compromised endpoint, Defender attack disruption stopped the attack dead in its tracks. From the first high-severity alert to completed isolation, after only 128 seconds, Defender cut off the attack chain before the second-stage payload could establish persistence or move beyond the host.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/learn.microsoft.com\/en-us\/defender-xdr\/automatic-attack-disruption\">Attack disruption<\/a>&nbsp;has proven highly effective at stopping multistage, cross-domain attacks by disrupting the attacker\u2019s ability to move across the environment. In many identity-driven attack scenarios, containing the compromised user is enough to shut down the attack chain, preventing lateral movement and limiting the attacker\u2019s ability to access additional systems, identities, and resources.<\/p>\n<p class=\"wp-block-paragraph\">However, we are increasingly seeing a different class of high-severity incidents that begin with initial access directly on the device. Once adversaries establish a foothold on an endpoint, they can plant multiple persistence mechanisms and continue operating locally on the machine. This means that acting against the user\u2019s identity alone is no longer enough to dismantle the threat.<\/p>\n<p class=\"wp-block-paragraph\">In these scenarios, the attacker has multiple ways to communicate and operate on the device beyond the user entity; the malicious code is already executing locally&nbsp;on the machine. The attacker doesn\u2019t have to move laterally immediately; they can establish persistence, steal credentials, inject into processes, and prepare follow-on stages directly from the compromised endpoint itself.<\/p>\n<p class=\"wp-block-paragraph\">Previously, stopping these attacks required manual triage and response, giving attackers time to advance. Device isolation closes this gap by automatically correlating signals, assessing the threat, and isolating the compromised device within seconds.<\/p>\n<p class=\"wp-block-paragraph\">Traditional response approaches often depend on static playbooks triggered by individual alerts and maintained through manual tuning. Attack disruption instead uses AI-driven correlation and real-time analysis to identify multi-stage attacks by connecting signals across the environment before taking action. Device isolation is enforced only when the disruption pipeline reaches a high-confidence verdict\u2014a threshold maintained at 99% precision.<\/p>\n<h2 class=\"wp-block-heading\" id=\"what-is-device-isolation\">What is device isolation?<\/h2>\n<p class=\"wp-block-paragraph\">When Microsoft Defender determines with high confidence that an endpoint is compromised, it isolates the device to immediately stop attacker activity and reduce the risk of further impact, such as data exfiltration and lateral movement.<\/p>\n<h3 class=\"wp-block-heading\" id=\"what-happens-during-device-isolation\">What happens during device Isolation<\/h3>\n<p class=\"wp-block-paragraph\">When a device is isolated, all external network connectivity is blocked while maintaining access to required security services like Microsoft Defender for Endpoint. Selective isolation is supported, allowing customer-defined services or exclusions to continue functioning.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/learn.microsoft.com\/en-us\/defender-endpoint\/respond-machine-alerts#isolate-device---automatic-attack-disruption-preview\">Automatic device isolation<\/a> is scoped to the affected device (supported today on onboarded MDE workstations), time-limited, and operator-controlled. Security teams can review context, take follow-up actions, and manually release isolation when it\u2019s safe to do so.<\/p>\n<h3 class=\"wp-block-heading\" id=\"why-it-matters\">Why it matters<\/h3>\n<p class=\"wp-block-paragraph\">Device isolation is a powerful containment control because it disrupts the attack regardless of how the device was compromised or what the attacker planned to do next. A single action cuts off network access, breaking lateral movement, command and control, credential theft, and rapid encryption\u2013effectively stopping hands-on activity and preventing spread to other systems. It is designed to work hand in hand with user containment. Isolating only the device or only the user leaves gaps; together, each one makes up for the weaknesses of the other, thereby mitigating these gaps to more effectively contain the attack.<\/p>\n<h2 class=\"wp-block-heading\" id=\"case-study-qnet\">Case study: QNET<\/h2>\n<p class=\"wp-block-paragraph\">QNET is a global direct-selling company with a distributed workforce and a lean security operations center (SOC).&nbsp;Like most teams of its size, QNET runs Defender with attack disruption enabled and relies on it to handle the first five minutes of a high-severity incident so analysts can focus on finding the root cause.<\/p>\n<p class=\"wp-block-paragraph\">In the incident detailed here, attack disruption proved decisive: it stopped a multi-stage attack on a single endpoint within 128 seconds by automatically enforcing device isolation, its newest disruption action. Without this autonomous disruption, the human-in-the-loop delay could have been the difference between a contained initial living-off-the-land binary (LOLBin) execution and a fully detonated second-stage payload that had achieved credential theft and persistence.<\/p>\n<h3 class=\"wp-block-heading\" id=\"in-the-customer-s-words\"><strong>In the customer\u2019s words<\/strong><\/h3>\n<p class=\"wp-block-paragraph\">\u201cAt QNET, we\u2019ve seen a real impact from Microsoft\u2019s attack disruption capability. During a recent incident, the device isolation was triggered almost immediately, which gave us confidence that the threat was contained early before it had any chance to spread.<\/p>\n<p class=\"wp-block-paragraph\">What stood out for us is how this changes the way the team operates. Instead of racing against time to investigate and contain an active threat, <strong>my team can step in knowing the situation is already under control<\/strong>. That shift allows us to focus more on root cause analysis and remediation, rather than spending critical time trying to piece together what\u2019s happening while the risk is still ongoing.<\/p>\n<p class=\"wp-block-paragraph\">From a day-to-day SOC perspective, it makes our response more efficient and far less reactive. The alerts are clear, the actions are meaningful, and the disruption happens early enough to actually make a difference, not after the damage is done.<\/p>\n<p class=\"wp-block-paragraph\">Overall, it\u2019s helped us streamline our incident response and reduce exposure, while giving the team more breathing room to focus on what really matters.\u201d<\/p>\n<p class=\"wp-block-paragraph\">\u2014 &nbsp;Ben Bredenkamp, Group CIO, <a href=\"https:\/\/www.qigroup.com\/business-focus\/empowering-entrepreneurship\/\">QI Group<\/a><\/p>\n<h2 class=\"wp-block-heading\" id=\"attack-chain-overview\">Attack chain overview<\/h2>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/08\/image-41-1024x556.webp\" alt class=\"wp-image-148991 webp-format\" srcset=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/08\/image-41-1024x556.webp 1024w, https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/08\/image-41-300x163.webp 300w, https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/08\/image-41-768x417.webp 768w, https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/08\/image-41-1536x833.webp 1536w, https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/08\/image-41-2048x1111.webp 2048w\" data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/08\/image-41-1024x556.webp\"><\/figure>\n<figure class=\"wp-block-table\">\n<table>\n<tbody readability=\"22\">\n<tr readability=\"7\">\n<td>08:30 \u2013 09:22<\/td>\n<td>Baseline<\/td>\n<td>A user opened a malicious file, likely delivered through email or browser download. The file executed <em>mshta.exe<\/em>, a legitimate Windows utility commonly abused by attackers. The <em>mshta.exe<\/em> process contacted an attacker-controlled URL and retrieved a second-stage payload. Persistence artifacts were then prepared (RunMRU activity was observed shortly afterward).<\/td>\n<\/tr>\n<tr readability=\"7\">\n<td>09:23:20<\/td>\n<td>Initial Access \/ Execution<\/td>\n<td>The malicious second stage executed through <em>mshta.exe<\/em>, establishing code execution on the device. Observed activity included suspicious command execution and user-level persistence behavior (RunMRU registry interaction). &nbsp;<\/td>\n<\/tr>\n<tr readability=\"7.5\">\n<td>09:23:20<\/td>\n<td>Detection<\/td>\n<td readability=\"8\">Two independent Defender detection engines triggered within the same second:<\/p>\n<p>\u2013 Behavioral\/execution-based detection flagged suspicious command activity (RunMRU abuse).<\/p>\n<p>\u2013 The correlation engine identified the activity pattern as malicious and consistent with real attack behavior (not benign tooling usage). &nbsp;<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"8\">\n<td>09:25:02<\/td>\n<td>Disruption decision<\/td>\n<td>The disruption pipeline correlated the alerts, evaluated the threat model (single endpoint, no lateral movement signs, malicious code already executing under user context), and selected device isolation as the action most likely to immediately contain the attack. &nbsp;<\/td>\n<\/tr>\n<tr readability=\"4\">\n<td>09:25:16<\/td>\n<td>Playbook start<\/td>\n<td>Defender autonomously initiated the IsolateDevice response playbook \u2013 the same containment action a SOC analyst would trigger manually \u2013 with full audit logging and a built-in auto-release mechanism to prevent prolonged business impact. &nbsp;<\/td>\n<\/tr>\n<tr readability=\"5\">\n<td>09:25:28<\/td>\n<td>Device isolated<\/td>\n<td>The IsolateDevice action completed successfully. The endpoint was cut off from all external and internal network communication, allowing only Defender management traffic. Communication with attacker-controlled infrastructure was immediately terminated. &nbsp;<\/td>\n<\/tr>\n<tr readability=\"8\">\n<td>09:25 \u2013 onward<\/td>\n<td>Post-isolation<\/td>\n<td>No additional malicious activity was observed. The mshta-launched payload was unable to continue execution, retrieve additional stages, or establish persistence. With no lateral movement or follow-on activity, the incident remained fully contained to a single endpoint. The SOC inherits a contained incident. &nbsp;<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p class=\"wp-block-paragraph\">Total time from first detection to enforced isolation: 128 seconds.<\/p>\n<h3 class=\"wp-block-heading\" id=\"the-results\">The results<\/h3>\n<p class=\"wp-block-paragraph\">To summarize the results of the new device isolation response action:<\/p>\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><strong>From first detection, Defender isolated the device in just 128 seconds.<\/strong><\/li>\n<li class=\"wp-block-list-item\"><strong>No second-stage payloads<\/strong> were observed after isolation. The mshta process was orphaned at the network layer; there was no outbound C2, and no follow-on download.<\/li>\n<li class=\"wp-block-list-item\"><strong>No lateral movement attempts<\/strong> were observed before or after isolation.<\/li>\n<li class=\"wp-block-list-item\"><strong>No SOC actions were required<\/strong> during the disruption window. The QNET SOC analyst who picked up the incident inherited an already-contained host and a complete action timeline.<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading\" id=\"mitre-att-ck-techniques-observed\">MITRE ATT&amp;CK techniques observed<\/h2>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<td>Tactic<\/td>\n<td>Technique ID<\/td>\n<td>Technique name<\/td>\n<td>Observed details<\/td>\n<\/tr>\n<\/thead>\n<tbody readability=\"26\">\n<tr readability=\"8\">\n<td>Initial Access \/ Execution<\/td>\n<td>T1204.002<\/td>\n<td>User Execution: Malicious File<\/td>\n<td>User opened a malicious file delivered via browser download or email, resulting in execution of <em>mshta.exe<\/em> at approximately 09:23:20 UTC on device a3198469\u2026b13.<\/td>\n<\/tr>\n<tr readability=\"5\">\n<td>Defense Evasion<\/td>\n<td>T1218.005<\/td>\n<td>System Binary Proxy Execution: Mshta<\/td>\n<td>Signed Microsoft binary <em>mshta.exe<\/em> was abused to proxy execution of attacker-controlled HTA\/script content and evade application trust controls.<\/td>\n<\/tr>\n<tr readability=\"5\">\n<td>Command and Control<\/td>\n<td>T1071.001<\/td>\n<td>Application Layer Protocol: Web Protocols<\/td>\n<td><em>mshta.exe<\/em> initiated outbound HTTP\/HTTPS communication to attacker-controlled infrastructure to retrieve a second-stage payload.<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td>Execution<\/td>\n<td>T1059<\/td>\n<td>Command and Scripting Interpreter<\/td>\n<td>HTA-delivered script content executed through the <em>mshta.exe<\/em> host process, enabling attacker-controlled command execution in user context.<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td>Persistence<\/td>\n<td>T1112<\/td>\n<td>Modify Registry<\/td>\n<td>Suspicious RunMRU-related registry interaction indicated attempted user-level persistence preparation.<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td>Discovery \/ Execution<\/td>\n<td>T1057<\/td>\n<td>Process Discovery<\/td>\n<td>Defender behavioral detections observed suspicious command activity consistent with attacker reconnaissance and execution staging immediately after payload launch.<\/td>\n<\/tr>\n<tr readability=\"8\">\n<td>Impact Mitigation (Defender response)<\/td>\n<td>\u2013<\/td>\n<td>Device Isolation (Defender Automatic Attack Disruption)<\/td>\n<td>Defender correlated multiple high-confidence detections and autonomously executed the IsolateDevice response action at 09:25:16 UTC, completing isolation by 09:25:28 UTC.<\/td>\n<\/tr>\n<tr readability=\"5\">\n<td>Command and Control (Prevented)<\/td>\n<td>T1105<\/td>\n<td>Ingress Tool Transfer<\/td>\n<td>Isolation interrupted outbound connectivity before additional payload stages or tooling could be retrieved from attacker infrastructure.<\/td>\n<\/tr>\n<tr readability=\"5\">\n<td>Lateral Movement (Prevented)<\/td>\n<td>TA0008<\/td>\n<td>Lateral Movement<\/td>\n<td>No evidence of lateral movement activity was observed before containment; device isolation prevented any subsequent propagation opportunities.<\/td>\n<\/tr>\n<tr readability=\"4\">\n<td>Persistence (Prevented)<\/td>\n<td>TA0003<\/td>\n<td>Persistence<\/td>\n<td>After isolation, no additional persistence artifacts or follow-on malicious processes were observed on the endpoint.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<h2 class=\"wp-block-heading\" id=\"references\">References<\/h2>\n<h2 class=\"wp-block-heading\" id=\"learn-more\">Learn more<\/h2>\n<p class=\"wp-block-paragraph\">For the latest security research from the Microsoft Threat Intelligence community, check out the&nbsp;<a href=\"https:\/\/aka.ms\/threatintelblog\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Threat Intelligence Blog<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">To get notified about new publications and to join discussions on social media, follow us on&nbsp;<a href=\"https:\/\/www.linkedin.com\/showcase\/microsoft-threat-intelligence\" target=\"_blank\" rel=\"noreferrer noopener\">LinkedIn<\/a>,&nbsp;<a href=\"https:\/\/x.com\/MsftSecIntel\" target=\"_blank\" rel=\"noreferrer noopener\">X (formerly Twitter)<\/a>, and&nbsp;<a href=\"https:\/\/bsky.app\/profile\/threatintel.microsoft.com\" target=\"_blank\" rel=\"noreferrer noopener\">Bluesky<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">To hear stories and insights from the Microsoft Threat Intelligence community about the ever-evolving threat landscape, listen to the&nbsp;<a href=\"https:\/\/thecyberwire.com\/podcasts\/microsoft-threat-intelligence\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Threat Intelligence podcast<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">Review\u202four\u202fdocumentation\u202fto learn\u202fmore about our real-time protection capabilities and see how\u202fto\u202fenable them within your\u202forganization.\u202f\u202f&nbsp;<\/p>\n<p> READ MORE <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/08\/04\/129-seconds-disruption-microsoft-defender-stops-ransomware-qnet\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft Defender automatically isolated a compromised QNET endpoint in 128 seconds, stopping a multi-stage attack before the payload could persist or spread.<br \/>\nThe post 128 Seconds to disruption: Microsoft Defender stops ransomware at QNET\u00a0 appeared first on Microsoft Security Blog. READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[276],"tags":[],"class_list":["post-61223","post","type-post","status-publish","format-standard","hentry","category-microsoft-secure"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>128 Seconds to disruption: Microsoft Defender stops ransomware at QNET\u00a0 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/128-seconds-to-disruption-microsoft-defender-stops-ransomware-at-qnet\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"128 Seconds to disruption: Microsoft Defender stops ransomware at QNET\u00a0 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/128-seconds-to-disruption-microsoft-defender-stops-ransomware-at-qnet\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-04T17:54:04+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"432\" \/>\n\t<meta property=\"og:image:height\" content=\"435\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/128-seconds-to-disruption-microsoft-defender-stops-ransomware-at-qnet\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/128-seconds-to-disruption-microsoft-defender-stops-ransomware-at-qnet\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"128 Seconds to disruption: Microsoft Defender stops ransomware at QNET\u00a0\",\"datePublished\":\"2026-08-04T17:54:04+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/128-seconds-to-disruption-microsoft-defender-stops-ransomware-at-qnet\\\/\"},\"wordCount\":1620,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/128-seconds-to-disruption-microsoft-defender-stops-ransomware-at-qnet\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.microsoft.com\\\/en-us\\\/security\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/image-41-1024x556.webp\",\"articleSection\":[\"Microsoft Secure\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/128-seconds-to-disruption-microsoft-defender-stops-ransomware-at-qnet\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/128-seconds-to-disruption-microsoft-defender-stops-ransomware-at-qnet\\\/\",\"name\":\"128 Seconds to disruption: Microsoft Defender stops ransomware at QNET\u00a0 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/128-seconds-to-disruption-microsoft-defender-stops-ransomware-at-qnet\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/128-seconds-to-disruption-microsoft-defender-stops-ransomware-at-qnet\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.microsoft.com\\\/en-us\\\/security\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/image-41-1024x556.webp\",\"datePublished\":\"2026-08-04T17:54:04+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/128-seconds-to-disruption-microsoft-defender-stops-ransomware-at-qnet\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/128-seconds-to-disruption-microsoft-defender-stops-ransomware-at-qnet\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/128-seconds-to-disruption-microsoft-defender-stops-ransomware-at-qnet\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.microsoft.com\\\/en-us\\\/security\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/image-41-1024x556.webp\",\"contentUrl\":\"https:\\\/\\\/www.microsoft.com\\\/en-us\\\/security\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/image-41-1024x556.webp\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/128-seconds-to-disruption-microsoft-defender-stops-ransomware-at-qnet\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"128 Seconds to disruption: Microsoft Defender stops ransomware at QNET\u00a0\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"128 Seconds to disruption: Microsoft Defender stops ransomware at QNET\u00a0 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/128-seconds-to-disruption-microsoft-defender-stops-ransomware-at-qnet\/","og_locale":"en_US","og_type":"article","og_title":"128 Seconds to disruption: Microsoft Defender stops ransomware at QNET\u00a0 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/128-seconds-to-disruption-microsoft-defender-stops-ransomware-at-qnet\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2026-08-04T17:54:04+00:00","og_image":[{"width":432,"height":435,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/128-seconds-to-disruption-microsoft-defender-stops-ransomware-at-qnet\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/128-seconds-to-disruption-microsoft-defender-stops-ransomware-at-qnet\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"128 Seconds to disruption: Microsoft Defender stops ransomware at QNET\u00a0","datePublished":"2026-08-04T17:54:04+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/128-seconds-to-disruption-microsoft-defender-stops-ransomware-at-qnet\/"},"wordCount":1620,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/128-seconds-to-disruption-microsoft-defender-stops-ransomware-at-qnet\/#primaryimage"},"thumbnailUrl":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/08\/image-41-1024x556.webp","articleSection":["Microsoft Secure"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/128-seconds-to-disruption-microsoft-defender-stops-ransomware-at-qnet\/","url":"https:\/\/www.threatshub.org\/blog\/128-seconds-to-disruption-microsoft-defender-stops-ransomware-at-qnet\/","name":"128 Seconds to disruption: Microsoft Defender stops ransomware at QNET\u00a0 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/128-seconds-to-disruption-microsoft-defender-stops-ransomware-at-qnet\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/128-seconds-to-disruption-microsoft-defender-stops-ransomware-at-qnet\/#primaryimage"},"thumbnailUrl":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/08\/image-41-1024x556.webp","datePublished":"2026-08-04T17:54:04+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/128-seconds-to-disruption-microsoft-defender-stops-ransomware-at-qnet\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/128-seconds-to-disruption-microsoft-defender-stops-ransomware-at-qnet\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/128-seconds-to-disruption-microsoft-defender-stops-ransomware-at-qnet\/#primaryimage","url":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/08\/image-41-1024x556.webp","contentUrl":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/08\/image-41-1024x556.webp"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/128-seconds-to-disruption-microsoft-defender-stops-ransomware-at-qnet\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"128 Seconds to disruption: Microsoft Defender stops ransomware at QNET\u00a0"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/61223","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=61223"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/61223\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=61223"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=61223"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=61223"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}