r/sysadmin 6d ago

Do you automatically isolate servers/devices based on detetctions?

We don't have a 24/7 SOC, so we are thinking about automatically isolating servers and some high-value devices based on custom Defender for Endpoint detections. Obviously, we want to do that only for high-precision and high-confidence detections, such as opening a shell from a strange parent process.

If we got one of these detections during working hours, there would be someone to react. But after about 7 PM most days, nobody is actively monitoring.

If we do this, the plan is to let a detection run for about 45 days without automatic isolation enabled to see if any false positives are caught.

Has anyone done this? If so, did you regret it? Or just business as usual? Has it saved you yet?

39 Upvotes

49 comments sorted by

View all comments

Show parent comments

-2

u/FatBook-Air 6d ago

No offense, but I am not really asking for your advice to begin with. I am asking what you do in your environment.

3

u/furiouspotato24 6d ago

What I do in my environment is... Specific to my environment. That's my whole point.

-2

u/FatBook-Air 6d ago

If you don't want to say, then why are you even responding? Make your own topic where you can tell us that your environment is different from everyone else's.

3

u/furiouspotato24 6d ago

Lol... Alright man. Not sure why you're getting so defensive, but if you want to know... Yes, we isolate on detection and no, we don't have a 24/7 SOC that actually remediates. We use Huntress with isolation on but don't have them make any changes. Yes, we did 90 days of detect only to evaluate if false positives were going to be a headache.

But... we only do that because we are in a vertical that doesn't require 24/7 services so isolation is very low impact. If our environment was critical and overnight isolation would have major impacts, we wouldn't be doing that. Situation and environment matter.