

Behavior monitoring alerts appear in the Microsoft 365 Defender alongside all other alerts and can be effectively investigated.

With behavior monitoring, Microsoft Defender for Endpoint on Linux protection is expanded to generically intercept whole new classes of threats such as ransom, sensitive data collection, crypto mining, and others. Effectiveness of this new enhanced capability was initially highlighted in the independent MITRE 2021 evaluation. These behavior-based signals will act as additional runtime signals for our cloud-powered machine learning models and for effective runtime protection.

The enhanced ability to correlate events and behaviors across multiple processes allows us to more generically detect and block malware based on their behavioral classification. These enhancements bring immediate ability to closely monitor processes, file system activities, and process interactions within the system. This new preventive functionality complements our existing strong content-based capabilities with behavior monitoring and runtime process memory scanning. Antivirus behavior monitoring is now generally available on Linux Turn on preview features to access this expanded TVM coverage.Ĥ. TVM for Debian 9+ is now in public preview. We are further expanding our Linux threat and vulnerability management to support Debian Linux distribution. Threat and vulnerability management for Debian distro is now in public preview
FEDORA PROCESS MONITOR HOW TO
How to get started with public preview for Linux RHEL6.7+, CentOS 6.7+ The minimum product version is 101.45.13.įor more information on the deployment details for these new distros, see the Microsoft Defender for Endpoint (Linux) deployment documentation. TVM coverage will be expanded with Amazon Linux and Fedora in coming months. The complete set of the previously released AV and EDR capabilities now applies to these newly added Linux distributions. What capabilities are available for Amazon Linux 2 and Fedora 33+ Additionally, the public preview of RHEL6.7+, CentOS 6.7+ is now available. In response to this feedback, today we are extending the supported matrix to include Amazon Linux 2 and Fedora 33+. Many Microsoft Defender for Endpoint customers requested to broaden the supported Linux distribution matrix with Amazon Linux, Fedora, and down-level RHEL.

Additional Linux Server distributions are now supported Turn on the preview features to see this capability in action.Ģ. Just a few days ago we enhanced our Linux detection and response with live response. With recent Microsoft Defender for Endpoint on Linux integration into Azure Security Center, the benefits of our Linux EDR and TVM now extend to Azure Defender customers.ġ. Linux EDR live response is now in public preview
FEDORA PROCESS MONITOR FULL
Microsoft protection for your Linux estate is getting an impressive boost across the full spectrum of the security suite. We are thrilled to share the latest news about Microsoft Defender for Endpoint on Linux next generation protection, endpoint detection and response (EDR), threat and vulnerability management (TVM).
