S01E42 - Advanced Threat Hunting with Microsoft Defender ATP (I.T)

preview_player
Показать описание
00:00 - Intro
01:08 - Microsoft Defender Security Center discussion
07:31 - Live response session demo
12:45 - startupfolders command
16:20 - getfile/fileinfo command
22:22 - Investigate entities on devices using live response
24:50 - Live response command examples
25:22 - remediate command
31:50 - analyze command
35:40 - Timeline
37:17 - Security agents discussion
42:24 - Wrapping up

Visit our websites and social media for more or to get in touch with us

Steve Hosking - Microsoft EM+S MVP

Adam Gross - Microsoft EM MVP

Ben Reader
Рекомендации по теме
Комментарии
Автор

Curious when you went too Menu\Programs\StartUp can you setup a advanced threat hunt query for all items created on all devices in that folder for review?

jstump
Автор

Does Microsoft defender work alongside other antivirus such as bitdefender gravity zone?

wnfaknd