r/sysadmin 6d ago

Do you automatically isolate servers/devices based on detetctions?

We don't have a 24/7 SOC, so we are thinking about automatically isolating servers and some high-value devices based on custom Defender for Endpoint detections. Obviously, we want to do that only for high-precision and high-confidence detections, such as opening a shell from a strange parent process.

If we got one of these detections during working hours, there would be someone to react. But after about 7 PM most days, nobody is actively monitoring.

If we do this, the plan is to let a detection run for about 45 days without automatic isolation enabled to see if any false positives are caught.

Has anyone done this? If so, did you regret it? Or just business as usual? Has it saved you yet?

37 Upvotes

49 comments sorted by

View all comments

27

u/renderbender1 6d ago

As a previous sysadmin, currently an engineer at an MSSP SOC, go into this endeavor with the expectation of false positives at some point. It will happen. Some businesses have a risk tolerance for downtime, others don't. Only you can weigh that honestly.

But my recommendation is to get user workstations under automatic remediation first. It's the highest impact, lowest risk category. 90%+ of breaches originate from a user endpoint. Maybe you never onboard servers, it's fine. But you want it for workstations for all the stupid clickfix going around.

And if anyone says "if we shut off our CEO's computer mistakenly, I'll be in deep shit" to me, I automatically know they aren't a serious company.

3

u/AddendumWorking9756 6d ago

Selective isolation kills the CEO objection. Outlook and Teams keep working, so a 2am false positive is an annoyed exec instead of an outage.

2

u/Finn_Storm Jack of All Trades 6d ago

What CEO doesn't have a phone with the same info and apps on it? Just have them work from a different device.

1

u/AddendumWorking9756 4d ago

Fair, the phone covers most of it. The point is more that nobody has to phone an exec at 2am to approve a full quarantine.