Skip to content
ms-blog-single-bg

Microsoft Defender vs Mesa

Shashi Prakash
Shashi Prakash

Even the best tools have blind spots. Modern platforms like Microsoft Defender stop many threats, but some advanced phishing attacks still slip through.

We’ve seen it firsthand: four real-world attacks landed right in our inbox.

With LLM-powered detection and context engineering, Mesa flagged and quarantined them in seconds.

Understanding the Differences: Defender vs Mesa

Example 1: Business Email Compromise

Summary: An executive impersonation email evaded Microsoft Defender’s detection and reached the recipient’s inbox. The rule-based system lacked the contextual language analysis needed to identify the impersonation and malicious intent.

Tactics, Techniques, and Procedures

  • Executive Name impersonation
  • Sender domain has high reputation using GMail as service provider
  • Email has no links or attachments in order to bypass filters.
  • Email uses simple language with a urgent call to action

Key Advantages with enhanced LLMs

  • Detects even minor variations in language used in BEC attacks
  • Detects executive name impersonation based on organization’s directory fed through RAG models
  • Saves analyst time for writing and deploying new detection rules (10 minutes per incident)

Detection Gap with rule-based system (Microsoft)

Detection with LLM + additional context (Mesa)

Example 2: Credential Phishing

Summary: A sophisticated phishing email impersonating Wells Fargo bypassed Microsoft Defender’s detection by using a legitimate, compromised email service and redirecting through trusted domains. The email passed all authentication checks while attempting to steal credentials through a fake file-sharing notification.

Tactics, Techniques, and Procedures

  • Sender Reputation hijacking: The email originated from a legitimate business whose email service was compromised. Since there was no prior threat intelligence on the sending domain, it didn’t raise any flags.
  • Authentication passed: Because the attacker used a trusted email service, all the usual checks (SPF, DKIM, DMARC) looked good — nothing seemed off.
  • URL Reputation hijacking: The link didn’t go straight to a phishing site directly but got redirected through a legitimate domain.

Key Advantages with enhanced LLMs

  • Detects mismatch between sender domain and claimed brand (Wells Fargo) without any rule updates.
  • Detects intent of natural language claiming urgency.
  • Detects visual indicators like ‘malicious link disguised as a button’ by doing image analysis.
  • Saves analyst time for writing and deploying new detection rules (20 minutes per incident)

Detection Gap with rule-based system (Microsoft)

Detection with LLM + additional context (Mesa)

Example 3: Ransomware

Summary: A ransomware notification email impersonating RSA Security bypassed Microsoft Defender by using a compromised legitimate domain and passing authentication checks. The email claimed files were encrypted and directed victims to download malicious “recovery” tools, exploiting trust in the RSA brand.

Tactics, Techniques, and Procedures
  • Brand impersonation: Email falsely claims to be from RSA Security, a trusted cybersecurity company
  • Legitimate domain compromise: Uses “bitwarden-notifications.com” which appears related to legitimate password manager
  • Authentication bypass: Passes SPF, DKIM, and DMARC checks due to compromised legitimate infrastructure
  • Psychological manipulation: Creates urgency by claiming files are already encrypted and offers immediate “solution”
Key Advantages with enhanced LLMs
  • Detects brand impersonation inconsistencies (RSA branding from non-RSA domain)
  • Identifies ransomware language patterns and urgency tactics in natural language
  • Recognizes suspicious file encryption claims and download prompts
  • Cross-references sender reputation against claimed brand identity
  • Saves analyst time for writing and deploying new detection rules (15 minutes per incident)

Detection Gap with rule-based system (Microsoft)

Detection with LLM + additional context (Mesa)

Example 4: Survey Scam

Summary: A prize scam email impersonating Argos retail chain bypassed Microsoft Defender by using legitimate notification services and social engineering tactics. The email offered fake £3,000 prizes for completing surveys, targeting users with convincing brand imagery and urgent calls to action.

Tactics, Techniques, and Procedures
  • Brand impersonation: Falsely uses Argos branding and logo to appear legitimate
  • Social engineering: Offers attractive monetary prize (£3,000) to entice participation
  • Legitimate service abuse: Uses notification services that pass basic reputation checks
  • Urgency creation: Implies limited-time opportunity to pressure quick action
  • Survey pretext: Uses familiar survey format to seem like legitimate market research
Key Advantages with enhanced LLMs
  • Detects brand impersonation through domain-brand mismatch analysis
  • Identifies unrealistic prize offers and scam language patterns
  • Recognizes survey scam social engineering tactics
  • Analyzes visual elements for brand consistency and authenticity
  • Cross-references sender domain against legitimate brand communications
  • Saves analyst time for writing and deploying new detection rules (10 minutes per incident)

Detection Gap with rule-based system (Microsoft)

Detection with LLM + additional context (Mesa)

These examples highlight that since Microsoft Defender relies primarily on signature-based and rule-based heuristics, these are insufficient against zero-day and polymorphic phishing campaigns. Mesa’s LLM-driven natural language processing, semantic embeddings, and retrieval-augmented analysis to detect anomalies in sender authenticity, linguistic patterns, and visual artifacts that bypass static filters. This multi-modal, context-aware architecture not only hardens defenses against evolving threats but also reduces analyst triage time by eliminating manual rule creation and accelerating incident response.

Discover more from Mesa Security

Subscribe now to keep reading and get access to the full archive.

Continue reading