I recently had a malware alert on my Azure VM running Windows 10. The malware has been removed, but I would like help completing a forensic analysis of the file path that had the malware alert

Matt Riddle 20 Reputation points
2025-03-29T18:17:31.4766667+00:00

I recently had a malware alert on my Azure VM running Windows 10. The malware has been removed, but I would like help completing a forensic analysis of the file path that had the malware alert. My company would like more information on how this malware made it way to our VM, when we are on a VPN with limited access. We wish to find out more information, in order to remediate and prevent any more alerts in the future.

How do I go about getting Microsoft assistance with this process?

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
0 comments No comments
{count} votes

Accepted answer
  1. Marcin Policht 50,895 Reputation points MVP Volunteer Moderator
    2025-03-29T18:21:45.17+00:00

    You'd need to enroll for CWPP (and CSPM) of Microsoft Defender for Cloud (in particular, Defender for Servers)

    More at https://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-cloud-introduction

    and

    https://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-servers-overview


    If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

    hth

    Marcin

    1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Sanoop M 4,310 Reputation points Moderator
    2025-03-31T03:05:19.15+00:00

    Hello @Matt Riddle ,

    In addition to the information provided by @Marcin Policht , please refer to the below documents related to the Overview of Agentless malware scanning for Virtual Machines in Microsoft Defender for Cloud which will be helpful.

    Agentless malware scanning for machines in Microsoft Defender for Cloud - Microsoft Defender for Cloud | Microsoft Learn

    Enable agentless scanning for VMs - Microsoft Defender for Cloud | Microsoft Learn

    I hope this above information provided is helpful. Please feel free to reach out if you have any further questions.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.