I recently had a malware alert on my Azure VM running Windows 10. The malware has been removed, but I would like help completing a forensic analysis of the file path that had the malware alert

Matt Riddle 20 Reputation points
2025-03-29T18:17:31.4766667+00:00

I recently had a malware alert on my Azure VM running Windows 10. The malware has been removed, but I would like help completing a forensic analysis of the file path that had the malware alert. My company would like more information on how this malware made it way to our VM, when we are on a VPN with limited access. We wish to find out more information, in order to remediate and prevent any more alerts in the future.

How do I go about getting Microsoft assistance with this process?

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,522 questions
0 comments No comments
{count} votes

Accepted answer
  1. Marcin Policht 44,755 Reputation points MVP
    2025-03-29T18:21:45.17+00:00

    You'd need to enroll for CWPP (and CSPM) of Microsoft Defender for Cloud (in particular, Defender for Servers)

    More at https://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-cloud-introduction

    and

    https://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-servers-overview


    If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

    hth

    Marcin

    1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Sanoop M 2,660 Reputation points Microsoft External Staff
    2025-03-31T03:05:19.15+00:00

    Hello @Matt Riddle ,

    In addition to the information provided by @Marcin Policht , please refer to the below documents related to the Overview of Agentless malware scanning for Virtual Machines in Microsoft Defender for Cloud which will be helpful.

    Agentless malware scanning for machines in Microsoft Defender for Cloud - Microsoft Defender for Cloud | Microsoft Learn

    Enable agentless scanning for VMs - Microsoft Defender for Cloud | Microsoft Learn

    I hope this above information provided is helpful. Please feel free to reach out if you have any further questions.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.