Microsoft Defender for Endpoint → Threats & antivirus, looking at a Severe Trojan: Trojan:JS/Nemucod.SFM!TB detection with multiple devices at risk But I am unable to find the alert on device. How to resolve this or how to get the Cause.

Irfan Hossain 20 Reputation points
2026-03-25T06:00:03.2666667+00:00

image

Microsoft Security | Microsoft Defender | Other

1 answer

Sort by: Oldest
  1. AI answer

    2026-03-25T06:00:18.2366667+00:00

    Use the threat entry in Threats & antivirus as the starting point, then pivot to the device and its timeline to understand cause and status.

    1. From Threats & antivirus, select the threat name Trojan:JS/Nemucod.SFM!TB.
    2. In the right pane, under Devices at risk, select one of the listed devices.
    3. This opens the device details view. Here you can:
      • Review Active alerts on that device.
      • Use the Alerts tab to see all alerts, their status, and whether they were remediated or not.
    4. Go to the Timeline tab for that device and filter around the First detected time shown in the threat pane. In the timeline:
      • Look for events such as Active threat detected, Remediation successful, or Remediation unsuccessful in the Additional information section.
      • Select the detection event to open Event details and, if needed, choose Hunt for related events to run an advanced hunting query for related activity on that endpoint.
    5. If the threat is shown as remediated but still appears under Threats & antivirus, confirm via the device timeline that remediation was successful and there are no recent related events. If remediation failed, use the device actions (for example, run an antivirus scan, isolate device, or collect an investigation package) from the device details pane to complete cleanup.
    6. For technical details and root-cause context about Trojan:JS/Nemucod.SFM!TB itself (behavior, files, mitigation), open the Threat reference link in the threat pane, which points to the Microsoft Defender Security Intelligence page for that malware family.

    This workflow lets you trace from the high-level threat entry down to the exact detection event on each device and determine both cause and current risk state.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.