Microsoft Linux support in the platform (Advanced Threat Protection), designed for proactive protection, tracking unpatched vulnerabilities, and detecting and eliminating malicious activity within the system.
The platform combines an antivirus suite, a network intrusion detection system, a vulnerability exploitation protection mechanism (including 0-day), an advanced isolation toolkit, additional application management tools, and a system for detecting potentially harmful activity.
A few days ago, the testing of Microsoft Defender ATP for macOS started. Functionality for platforms other than Windows is currently limited to the EDR component (), which is responsible for monitoring behavior and analyzing activity using machine learning techniques to detect potential attacks, as well as including tools for analyzing the consequences of attacks and responding to potential threats. The release of Microsoft Defender ATP for Linux is scheduled for next year, and a preview version was demonstrated last week at the Ignite 2019 conference.
Source: opennet.ru
