(no title)
deadso | 5 years ago
It can analyze an attackers moves within your network, figuring out what files they accessed, ways they pivoted, and other stuff. So not only would it detect that you got compromised, but the display will show you likely paths, names of users that are also compromised, mitigation steps, deployed persistence measures, etc.
So for Defender ATP to work optimally in a deployment that leverages linux nodes, or has users using linux as their daily driver, you need to support linux.
mrits|5 years ago
TA43|5 years ago
Defender, in its current state, rolls all of the above into one at a relatively competitive price point. Additionally, it receives new detections built off all the telemetry they get as a result of Windows Defender existing on almost every Win10 OS on the planet.
This leveraging of data on such a scale is letting Microsoft quickly become the market leader for threat detection & response.
deadso|5 years ago
mistrial9|5 years ago