Understanding alerts and incidents
EDR doesn’t simply record the telemetry for you to blindly sift through, however. MDE’s EDR capabilities are enhanced through a big data, cloud-based analytics engine. Leveraging the incredible volume of data available to Microsoft from the Windows and M365 ecosystems, behavioral signals are converted into detections and response recommendations. Threat intelligence from Microsoft internal sources, such as dedicated security researchers, Microsoft Threat Intelligence Center (MSTIC), and others, are combined with threat intelligence from multiple partners to identify new IOCs, IOAs, and attacker TTPs.
Cold snack
This big data approach allows trends that might go unnoticed in a smaller environment, or due to a low volume of relevant signals in any single environment, to still generate enough signals at a macro level for behavioral patterns to be identified and detections to be generated for all users of the product, regardless of...