<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Endpoint-Detection on CuraSec</title><link>https://curasec.metacog.co.kr/tags/endpoint-detection/</link><description>Recent content in Endpoint-Detection on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 05 Aug 2026 13:01:27 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/endpoint-detection/index.xml" rel="self" type="application/rss+xml"/><item><title>Microsoft Defender auto-isolates ransomware endpoint in 128 seconds</title><link>https://curasec.metacog.co.kr/insights/2026-08-05-128-seconds-to-disruption-microsoft-defender-stops-ransomwar/</link><pubDate>Wed, 05 Aug 2026 13:01:27 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-05-128-seconds-to-disruption-microsoft-defender-stops-ransomwar/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> The case illustrates how automated endpoint isolation can compress ransomware dwell time to under three minutes; worth reviewing your own EDR auto-containment thresholds against this benchmark.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item></channel></rss>