Monitoring with MDATP
Formerly known as Windows Defender, Microsoft Defender is the anti-malware solution that is shipped with Windows. It provides threat detection solutions for Windows desktops and servers, Linux, and macOS. Microsoft Defender, when combined with ATP, becomes the MDATP solution. MDATP not only allows organizations to detect threats, but also provides threat intelligence, analytics, and Endpoint Detection and Response (EDR), and includes automated investigations for the Security Operations Center (SOC) to follow up on alerts.
The capabilities of the MDATP solution can be broken down into the following areas:
- The Threat & Vulnerability Management feature discovers device vulnerability and misconfigurations using Microsoft Intelligent Security Graph. This provides real-time detection and response insights.
- Attack surface reduction is used to describe the technology for mitigation of potential attack surfaces using controls such as hardware-based...