With the Creators Fall release of Windows 10 last year, Microsoft confirmed the intention of offering their desktop customers a true end-to-end cyber security framework. Their mission defines the delivery of ‘protect, detect and respond’ across the entire Windows stack and the current version of Windows Defender Advanced Threat Protection (ATP) offers an impressive set of features. These include Smartscreen, Device Guard, Exploit Guard, Application Guard, and Application Control. The ATP upgrade also included a significant update to its antivirus capability.
2018 Windows Defender ATP Release
Microsoft has recently announced its new 2018 features for Windows Defender ATP. This upgrade begins to move them into the territory of more sophisticated Endpoint Detection Response (EDR) systems from vendors such as Carbon Black and Rapid7.
From alert to remediation in minutes
2018 Windows Defender ATP offers automated investigation and response that dramatically reduces the volume of alerts that security analysts must handle. It uses artificial intelligence to investigate alerts and references them against known behavioural patterns and malware signatures stored in the Microsoft Security library. If the threat is real and active, ATP takes appropriate steps to automatically remediate it. If the incident includes multiple machines, it automatically expands the investigation across the entire scope of breach and performs the required actions on all endpoint in parallel.
Microsoft 365 conditional access
Microsoft have worked with their Intune and Azure Active Directory (AAD) teams, to enrich one of the most popular security scenarios of Microsoft 365 conditional access. If a threat gets detected, access to sensitive business data from the device is blocked while the threat is still active. Available in the next update, the dynamic machine risk level will be used to define corporate access policies and prevent risk to corporate data. As an example, if a dangerous threat (including file less malware) lands on your endpoints, Windows Defender ATP can detect it and automatically protect your precious corporate information through conditional access. In parallel, it will also start an automated investigation to quickly remediate the threat. Once the threat is remediated, based on the preference set (automatic or reviewed), the risk level is set back to “no risk” and access is granted again.
Advanced Hunting
Microsoft have included a powerful query-based search designed to proactively hunt and investigate across the organisation’s processes and data. From new process creation, file modification, machine login, network communication, registry update, remediation actions and many other event types – all can be searched, identified and correlated.
The Future for ATP
These new Windows Defender ATP innovations place an emphasis on leveraging intelligence, cloud, and analytics to build deeper levels of advanced threat protection. Microsoft’s commitment to the EDR/MDR cause is being extended to its server family with Windows Defender ATP now being built into Windows Server 2019. They also have plans to extend the technology to macOS, Linux, iOS, and Android devices through the Microsoft Intelligent Security Association.


