Windows Defender ATP is a cloud based subscription service that provides advanced protection by analyzing events that occur across multiple endpoints to detect anomalies and known attack vectors. The solution is made up of the following main components:
- Endpoints: These collects and process behavioral signals from sensors built-in to the operating system (for example, kernel, memory, registry, file, and network communications) and send this sensor data to your private, isolated, cloud instance of Windows Defender ATP. They currently work with Windows 10, and support for Windows Server is coming soon.
- Cloud security analytics: This enables us to leverage big data, machine learning, and unique Microsoft views across the ...