build 7bbbddf7 | content blog-content@c8490fa · 338 posts | profiles 20 · corpus 267 | 0 skipped | | format
apiVersion: soultec.ch/v1kind: Solutionmetadata: name: endpoint-security/microsoft-defender-atp locale: en labels: vendor: Microsoft Defender for Endpoint capability/endpoint-security: 3.54 capability/security: 2.16 vendor/microsoft: 2.53 annotations: source: src/content/solutions/en/endpoint-security/microsoft-defender-atp.md route: /en/solutions/endpoint-security/microsoft-defender-atp/ schema: /nerd/schema/solutions.json markdown: /en/solutions/endpoint-security/microsoft-defender-atp.mdspec: title: Microsoft Defender tags: [endpoint-security, security] vendors: [microsoft] summary: >- Endpoint detection and response from the Microsoft stack. If you already have M365 E5, you have usually already licensed it. photoNeed: A security console on screen with real alerts in it, being triaged stub: false draft: false kind: product addon: false vendorName: Microsoft Defender for Endpoint status: current sections: - heading:

What it is

body: | Defender for Endpoint reads what actually happens on a device and reports sequences that do not fit. The analysis runs in Microsoft's cloud, and the signals come from the operating system itself rather than from an agent bolted on afterwards. - heading:

What it is for

body: | Estates that are on Microsoft anyway. The practical advantage is rarely detection quality; it is that identity, device management and endpoint security use the same groups and the same console. - heading:

What to watch

body: | Two things. Licensing first: the full feature set depends on the plan, and the difference between tiers is exactly the part you miss later. Then the first few weeks: backup agents, monitoring and home-grown scripts all look like attackers to an EDR. Those exceptions belong in writing, or in two years there is a rule set nobody wants to touch.status: corpus: 267 services: - {ref: services/modern-workplace, score: 0.81} - {ref: services/security, score: 0.76} - {ref: services/cloud, score: 0.41} posts: - {ref: posts/how-to-build-a-test-environment-for-opswat-metadefender-managed-file-transfer, score: 0.42} - {ref: posts/how-to-secure-your-dmz-with-a-proxy, score: 0.42} - {ref: posts/exagrid, score: 0.34} - {ref: posts/vmware-security-advisory, score: 0.27} - {ref: posts/vmware-security-advisory-vmsa-2024-0012, score: 0.27} - {ref: posts/vmware-security-advisory-vmsa-2022-0030, score: 0.27} experts: - {ref: experts/matthias-frech, score: 0.38} neighbours: - {ref: solutions/endpoint-security, score: 1.00} - {ref: solutions/endpoint-security/vmware-carbon-black, score: 0.70} - {ref: solutions/microsoft/microsoft-365, score: 0.49}
{ "apiVersion": "soultec.ch/v1", "kind": "Solution", "metadata": { "name": "endpoint-security/microsoft-defender-atp", "locale": "en", "labels": { "vendor": "Microsoft Defender for Endpoint", "capability/endpoint-security": "3.54", "capability/security": "2.16", "vendor/microsoft": "2.53" }, "annotations": { "source": "src/content/solutions/en/endpoint-security/microsoft-defender-atp.md", "route": "/en/solutions/endpoint-security/microsoft-defender-atp/", "schema": "/nerd/schema/solutions.json", "markdown": "/en/solutions/endpoint-security/microsoft-defender-atp.md" } }, "spec": { "title": "Microsoft Defender", "tags": [ "endpoint-security", "security" ], "vendors": [ "microsoft" ], "summary": "Endpoint detection and response from the Microsoft stack. If you already have M365 E5, you have usually already licensed it.", "photoNeed": "A security console on screen with real alerts in it, being triaged", "stub": false, "draft": false, "kind": "product", "addon": false, "vendorName": "Microsoft Defender for Endpoint", "status": "current" }, "sections": [ { "heading": "

What it is

",
"body": "Defender for Endpoint reads what actually happens on a device and reports sequences that do\nnot fit. The analysis runs in Microsoft's cloud, and the signals come from the operating\nsystem itself rather than from an agent bolted on afterwards." }, { "heading": "

What it is for

",
"body": "Estates that are on Microsoft anyway. The practical advantage is rarely detection quality;\nit is that identity, device management and endpoint security use the same groups and the\nsame console." }, { "heading": "

What to watch

",
"body": "Two things. Licensing first: the full feature set depends on the plan, and the difference\nbetween tiers is exactly the part you miss later. Then the first few weeks: backup agents,\nmonitoring and home-grown scripts all look like attackers to an EDR. Those exceptions\nbelong in writing, or in two years there is a rule set nobody wants to touch." } ], "status": { "corpus": 267, "services": [ { "ref": "services/modern-workplace", "score": "0.81" }, { "ref": "services/security", "score": "0.76" }, { "ref": "services/cloud", "score": "0.41" } ], "posts": [ { "ref": "posts/how-to-build-a-test-environment-for-opswat-metadefender-managed-file-transfer", "score": "0.42" }, { "ref": "posts/how-to-secure-your-dmz-with-a-proxy", "score": "0.42" }, { "ref": "posts/exagrid", "score": "0.34" }, { "ref": "posts/vmware-security-advisory", "score": "0.27" }, { "ref": "posts/vmware-security-advisory-vmsa-2024-0012", "score": "0.27" }, { "ref": "posts/vmware-security-advisory-vmsa-2022-0030", "score": "0.27" } ], "experts": [ { "ref": "experts/matthias-frech", "score": "0.38" } ], "neighbours": [ { "ref": "solutions/endpoint-security", "score": "1.00" }, { "ref": "solutions/endpoint-security/vmware-carbon-black", "score": "0.70" }, { "ref": "solutions/microsoft/microsoft-365", "score": "0.49" } ] }}
apiVersion = "soultec.ch/v1"kind = "Solution"[metadata]name = "endpoint-security/microsoft-defender-atp"locale = "en"[metadata.labels]vendor = "Microsoft Defender for Endpoint""capability/endpoint-security" = "3.54""capability/security" = "2.16""vendor/microsoft" = "2.53"[metadata.annotations]source = "src/content/solutions/en/endpoint-security/microsoft-defender-atp.md"route = "/en/solutions/endpoint-security/microsoft-defender-atp/"schema = "/nerd/schema/solutions.json"markdown = "/en/solutions/endpoint-security/microsoft-defender-atp.md"[spec]title = "Microsoft Defender"tags = ["endpoint-security", "security"]vendors = ["microsoft"]summary = "Endpoint detection and response from the Microsoft stack. If you already have M365 E5, you have usually already licensed it."photoNeed = "A security console on screen with real alerts in it, being triaged"stub = falsedraft = falsekind = "product"addon = falsevendorName = "Microsoft Defender for Endpoint"status = "current"[[sections]]heading = "

What it is

"
body = '''Defender for Endpoint reads what actually happens on a device and reports sequences that donot fit. The analysis runs in Microsoft's cloud, and the signals come from the operatingsystem itself rather than from an agent bolted on afterwards.'''[[sections]]heading = "

What it is for

"
body = '''Estates that are on Microsoft anyway. The practical advantage is rarely detection quality;it is that identity, device management and endpoint security use the same groups and thesame console.'''[[sections]]heading = "

What to watch

"
body = '''Two things. Licensing first: the full feature set depends on the plan, and the differencebetween tiers is exactly the part you miss later. Then the first few weeks: backup agents,monitoring and home-grown scripts all look like attackers to an EDR. Those exceptionsbelong in writing, or in two years there is a rule set nobody wants to touch.'''[status]corpus = 267[[status.services]]ref = "services/modern-workplace"score = "0.81"[[status.services]]ref = "services/security"score = "0.76"[[status.services]]ref = "services/cloud"score = "0.41"[[status.posts]]ref = "posts/how-to-build-a-test-environment-for-opswat-metadefender-managed-file-transfer"score = "0.42"[[status.posts]]ref = "posts/how-to-secure-your-dmz-with-a-proxy"score = "0.42"[[status.posts]]ref = "posts/exagrid"score = "0.34"[[status.posts]]ref = "posts/vmware-security-advisory"score = "0.27"[[status.posts]]ref = "posts/vmware-security-advisory-vmsa-2024-0012"score = "0.27"[[status.posts]]ref = "posts/vmware-security-advisory-vmsa-2022-0030"score = "0.27"[[status.experts]]ref = "experts/matthias-frech"score = "0.38"[[status.neighbours]]ref = "solutions/endpoint-security"score = "1.00"[[status.neighbours]]ref = "solutions/endpoint-security/vmware-carbon-black"score = "0.70"[[status.neighbours]]ref = "solutions/microsoft/microsoft-365"score = "0.49"
<?xml version="1.0" encoding="UTF-8"?><manifest kind="Solution"> <apiVersion>soultec.ch/v1</apiVersion> <metadata> <name>endpoint-security/microsoft-defender-atp</name> <locale>en</locale> <labels> <vendor>Microsoft Defender for Endpoint</vendor> <entry key="capability/endpoint-security">3.54</entry> <entry key="capability/security">2.16</entry> <entry key="vendor/microsoft">2.53</entry> </labels> <annotations> <source>src/content/solutions/en/endpoint-security/microsoft-defender-atp.md</source> <route>/en/solutions/endpoint-security/microsoft-defender-atp/</route> <schema>/nerd/schema/solutions.json</schema> <markdown>/en/solutions/endpoint-security/microsoft-defender-atp.md</markdown> </annotations> </metadata> <spec> <title>Microsoft Defender</title> <tags> <item>endpoint-security</item> <item>security</item> </tags> <vendors> <item>microsoft</item> </vendors> <summary>Endpoint detection and response from the Microsoft stack. If you already have M365 E5, you have usually already licensed it.</summary> <photoNeed>A security console on screen with real alerts in it, being triaged</photoNeed> <stub>false</stub> <draft>false</draft> <kind>product</kind> <addon>false</addon> <vendorName>Microsoft Defender for Endpoint</vendorName> <status>current</status> </spec> <sections> <section> <heading>

What it is

</heading>
<body>Defender for Endpoint reads what actually happens on a device and reports sequences that donot fit. The analysis runs in Microsoft's cloud, and the signals come from the operatingsystem itself rather than from an agent bolted on afterwards. </body> </section> <section> <heading>

What it is for

</heading>
<body>Estates that are on Microsoft anyway. The practical advantage is rarely detection quality;it is that identity, device management and endpoint security use the same groups and thesame console. </body> </section> <section> <heading>

What to watch

</heading>
<body>Two things. Licensing first: the full feature set depends on the plan, and the differencebetween tiers is exactly the part you miss later. Then the first few weeks: backup agents,monitoring and home-grown scripts all look like attackers to an EDR. Those exceptionsbelong in writing, or in two years there is a rule set nobody wants to touch. </body> </section> </sections> <status> <corpus>267</corpus> <services> <item> <ref>services/modern-workplace</ref> <score>0.81</score> </item> <item> <ref>services/security</ref> <score>0.76</score> </item> <item> <ref>services/cloud</ref> <score>0.41</score> </item> </services> <posts> <item> <ref>posts/how-to-build-a-test-environment-for-opswat-metadefender-managed-file-transfer</ref> <score>0.42</score> </item> <item> <ref>posts/how-to-secure-your-dmz-with-a-proxy</ref> <score>0.42</score> </item> <item> <ref>posts/exagrid</ref> <score>0.34</score> </item> <item> <ref>posts/vmware-security-advisory</ref> <score>0.27</score> </item> <item> <ref>posts/vmware-security-advisory-vmsa-2024-0012</ref> <score>0.27</score> </item> <item> <ref>posts/vmware-security-advisory-vmsa-2022-0030</ref> <score>0.27</score> </item> </posts> <experts> <item> <ref>experts/matthias-frech</ref> <score>0.38</score> </item> </experts> <neighbours> <item> <ref>solutions/endpoint-security</ref> <score>1.00</score> </item> <item> <ref>solutions/endpoint-security/vmware-carbon-black</ref> <score>0.70</score> </item> <item> <ref>solutions/microsoft/microsoft-365</ref> <score>0.49</score> </item> </neighbours> </status></manifest>
Solution · Microsoft

Microsoft Defender

The vendor calls it: Microsoft Defender for Endpoint

Endpoint detection and response from the Microsoft stack. If you already have M365 E5, you have usually already licensed it.

Topics Endpoint Security 3.54 Security 2.16
Vendors Microsoft 2.53
03Services
06Posts
02Capabilities
267Corpus

What it is

Defender for Endpoint reads what actually happens on a device and reports sequences that do not fit. The analysis runs in Microsoft’s cloud, and the signals come from the operating system itself rather than from an agent bolted on afterwards.

What it is for

Estates that are on Microsoft anyway. The practical advantage is rarely detection quality; it is that identity, device management and endpoint security use the same groups and the same console.

What to watch

Two things. Licensing first: the full feature set depends on the plan, and the difference between tiers is exactly the part you miss later. Then the first few weeks: backup agents, monitoring and home-grown scripts all look like attackers to an EDR. Those exceptions belong in writing, or in two years there is a rule set nobody wants to touch.

Posts about it

Who works with it

Do you work with this? Take a look at our open roles.