Microsoft is preparing to release its Advanced Threat Analytics (ATA) enterprise security system next month. It's a new way to prevent and protect against hacker attacks on corporate networks.
Since the latest preview release, Advanced Threat Analytics (ATA) chief technical officer Idan Plotnik said the application has 13 new features for improved threat detection.
“After installation, ATA immediately starts analyzing all relevant data, such as network traffic, collecting information about AD entities, and collecting relevant events from events in the Information Security Management System,” says Plotnik.
“Based on this analysis, the ATA creates a security graph and begins by identifying security issues, advanced attacks, or detecting abnormal behaviors.
When an attack is detected, ATA creates a timeline of the attack that makes it very easy for security analysts to understand the attack and identify where to focus their research efforts.”
The new application will be available as a standalone product or will be included in Microsoft's Enterprise Client Access License and Enterprise Mobility Suite. Additional features in the final version of Advanced Threat Analytics will include:
- Support for Windows Event Forwarding to get events directly from servers/workstations to the ATA gateway?
- Pass-The-Hash detection enhancements against corporate resources by combining DPI and logs analysis?
- Enhancements for the support of non-domain joined devices (and non-Windows) for detection and visibility;
- Performance improvements to support more traffic and events with ATA Gateway?
- Performance improvements to support more ATA Gateways per Center?
- Automatic name resolution process to match between computer names and IPs to help save investigation time?
- Improving inputs from the user to automatically adjust the detection process?
- Automatic detection for NAT devices?
- Automatic failover in case the Domain Controller is not reachable?
- System health monitoring and notifications providing the overall health state of the deployment as well as specific issues related to configuration, connectivity;
- Visibility into sites and locations where entities operate?
- Multi-domain support,
- And support for Single Label Domains.
If you are interested in the new Advanced Threat Analytics product, you can read more on Microsoft's blog.
