We're Hiring!
Take the next step in your career and work on diverse technology projects with cross-functional teams.
LEARN MORE
Mountain West Farm Bureau Insurance
office workers empowered by business technology solutions
BLOG
6
26
2017
3.1.2023

Windows Defender - Advance Threat Protection

Last updated:
9.16.2020
3.1.2023
No items found.

Published on March 22, 2017
Paul Keely (MVP)
Microsoft Azure Cloud Security Expert

Microsoft has developed the most amazing defense to Advanced Persistent Threats (APT’s) in the form of two technologies;

  1. Windows Defender – Advanced Threat Protection, to protect your Windows 10 endpoints.
  2. O365 – Advanced Threat Protection, to protect your 0365 environments.
    In this article, I am just going to look at the WD ATP version and will cover the O365 solution in the next article.

What is the problem that ATP is trying to solve?

If you are attacked, you need to answer three questions;

· How did it get here?

· What did it do?

· Where did it go?

ATP is going to show you who was attacked, what the attack was and where the attack has spread to.

ATP is built on the mindset of “Assume Breach” and is made up of 3 components;

1. A behavioral based sensor on Windows 10 Anniversary Edition (or higher)

2. Cloud security analytics portal in Azure (that you must connect your Win 10 devices too)

3. Microsoft and third party vendor’s, security intelligence

ATP is a game changer in term of leveling the playing field with the ever-evolving cyber security threats. ATP is a behavioral based sensor on all Windows 10 devices that looks for Advanced Persistent Threats (APT’s). Each client has its own ATP tenant in Azure that clients send data to. The sensor works alongside your Antivirus (AV) client to protect your endpoints. ATP works with the Microsoft AV agent, Windows Defender (Yes I know the naming is confusingL) and any other third party AV provider. This point of working alongside your current AV is important to note, it does not replace your AV.

One of the key features of ATP is that it assumes breach, not only does it not shy away from the fact, the primary focus of the ATP portal is detecting a breach, showing its timeline, helping you investigate the spread and giving you the tools to respond. ATP’s mindset is that attackers who have traditionally remained undetected in an organization for 100+ days will be outdated.

Access ATP

You access ATP through https://securitycenter.windows.com, and once on the portal screen ATP starts with an incident graph that will show you the files who’s “behavior” has been identified as inappropriate, attackers are using common files that are not identified as malware but are behaving in an inappropriate way.

ATP then has a cloud-based “Sandbox” called a detonation chamber. This isolated sandbox acts as a fully secure environment that will run the files and observe all the actions it takes thereafter. All of this is processed into an easy to read report.

ATP is also a forensic tool, as it will show you the attack and its timeline even if, as part of the attack, the program deletes itself.

You can buy ATP through a licensing SKU like E5 (please refer to your Microsoft account manager for this). Once you have signed up for the service you will receive on-boarding instructions via email that will help you get your subscription ready for deployment.

The sensor that is installed and optimized on your Windows 10 device needs to be able to talk to your cloud service and to do that a small configuration file must be deployed to your devices

Windows Defender ATP is a close relative of, but different to Office 365 ATP that is a similar service but for your Exchange Online environment and not for your Windows 10 endpoints. Office 365 ATP will block the spread of the attack using Exchange Online as the attack vector; this blocking capability is only being added to the Windows version as part of the latest Windows updated to Windows 10 (Creator update).

Recent Blog Posts

lunavi logo alternate white and yellow
4.5.2024
03
.
27
.
2024
Utilizing Bicep Parameter Files with ALZ-Bicep

Ready to achieve more efficient Azure Deployments? You can use Bicep parameters instead of JSON which opens new opportunities for deployment. Let Lunavi expert, Joe Thompson, show you how.

Learn more
lunavi logo alternate white and yellow
3.26.2024
03
.
04
.
2024
Anticipating Surges in Cyber Attacks and Bolstering Your InfoSec Defenses in 2024

Learn how to navigate 2024 with the right InfoSec defenses to protect your organization against a rising number of cyber attacks.

Learn more
lunavi logo alternate white and yellow
3.26.2024
01
.
03
.
2024
Microsoft Copilot is Re-Shaping the Innovation Frontier

Microsoft 365 Copilot has been released, and it's changing the way we work. More than OpenAI or ChatGPT, read how Copilot can seamlessly integrate with your workflow.

Learn more