
About this episode
What if Microsoft Defender not only detected attackers - but also fought back? Richard talks to Liz Tesch about Microsoft Defender Automatic Attack Disruption and Predictive Shielding. Liz talks about how attacks are often detected before the payload executes, but by the time humans can respond, far more damage has been done. Automatic Attack Disruption acts immediately on detection to limit the attacker by locking accounts, restricting access on a compromised server, and more. Predictive Shielding goes a step further by limiting attackers' ability to respond to the disruption by turning off GPO changes, disabling safe mode, and otherwise interfering with the typical actions that attackers take once they know they have been detected. Add AI to the mix, and everything gets more complicated. The black hats are using AI to attack, and Microsoft Defender XDR is using it to defend - the race is on!
Links
- Microsoft Defender XDR
- Automatic Attack Disruption
- Predictive Shielding
- Microsoft Sentinel
- Microsoft Defender for Identity
- Automatic Attack Disruption EBook
- Web Scale Graph Mining for Cyber Threat Intelligence Research Paper
- Local AI Agent Discovery with MDE
- Threat Hunting in Microsoft Sentinel
- Microsoft Defender for XDR Preview
- New Features for MDE
Recorded June 29, 2026
Get every episode summarized
Each time RunAs Radio publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from RunAs Radio

State of WSUS with Adam Marshall
RunAs Radio

Reimagining Intranets with Susan Hanley
RunAs Radio

Security Features of PowerShell 7 with Mike O'Neill
RunAs Radio

The Content Management System Landscape with Matt Garrepy
RunAs Radio