Planning and implementing MDE
The MDE security platform enables organizations to investigate and respond to advanced threats that target their enterprise networks. It does so by providing information about advanced attack detections based on behavioral patterns. The threats detected by MDE are interpreted in terms of a forensic timeline. This timeline is then used to build and maintain a threat intelligence knowledge base.
This is achieved by using endpoint behavioral sensors that collect signals from the Windows operating system and send that data to MDE. Then, cloud security analytics use machine learning techniques to translate the collected data into insights and provide recommendations on how to resolve advanced threats. Finally, threat intelligence activities are carried out by Microsoft hunters and security experts. This allows MDE to recognize the tools and methods employed by malicious actors and to alert administrators when similar behavior is detected.
MDE provides...