Additional Microsoft Defender tools and services that provide security across various platforms and environments
Use the threat entry in Threats & antivirus as the starting point, then pivot to the device and its timeline to understand cause and status.
- From Threats & antivirus, select the threat name
Trojan:JS/Nemucod.SFM!TB. - In the right pane, under Devices at risk, select one of the listed devices.
- This opens the device details view. Here you can:
- Review Active alerts on that device.
- Use the Alerts tab to see all alerts, their status, and whether they were remediated or not.
- Go to the Timeline tab for that device and filter around the First detected time shown in the threat pane. In the timeline:
- Look for events such as Active threat detected, Remediation successful, or Remediation unsuccessful in the Additional information section.
- Select the detection event to open Event details and, if needed, choose Hunt for related events to run an advanced hunting query for related activity on that endpoint.
- If the threat is shown as remediated but still appears under Threats & antivirus, confirm via the device timeline that remediation was successful and there are no recent related events. If remediation failed, use the device actions (for example, run an antivirus scan, isolate device, or collect an investigation package) from the device details pane to complete cleanup.
- For technical details and root-cause context about
Trojan:JS/Nemucod.SFM!TBitself (behavior, files, mitigation), open the Threat reference link in the threat pane, which points to the Microsoft Defender Security Intelligence page for that malware family.
This workflow lets you trace from the high-level threat entry down to the exact detection event on each device and determine both cause and current risk state.
References: