The recent discovery of a breach involving a connected SharePoint system, one that remained undetected for weeks, highlights a persistent and costly vulnerability in modern enterprise security: dwell time. Passive monitoring, which waits for an attacker to trip a known wire, is insufficient against adversaries who specialize in “living off the land” using legitimate administrative tools to blend with normal traffic. Every hour an attacker remains undetected inside a network exponentially increases the ultimate cost of the breach, moving from initial reconnaissance to privilege escalation, and ultimately, data exfiltration or ransomware deployment. The only effective countermeasure to prolonged dwell time is proactive threat hunting combined with instantaneous investigative execution: when an anomaly is detected, even a low-fidelity signal, the response cannot be a manual query process that takes hours to complete. Security teams need the capability to instantly execute deep, automated investigations that traverse historical data. Your AI SOC platform is built to compress this investigative lifecycle, transforming a fragmented hunt into a definitive answer, thereby minimizing exposure and preventing a foothold from becoming a catastrophic breach.

Source: https://www.microsoft.com/en-us/security/blog/2025/07/22/disrupting-active-exploitation-of-on-premises-sharepoint-vulnerabilities/