From 0e8b682bdb602e63fb5c9c621ba414ab57324d64 Mon Sep 17 00:00:00 2001 From: Dulce Montemayor Date: Tue, 30 Apr 2019 09:32:04 -0700 Subject: [PATCH] Bilbao TAN GA updates (#51) Bilbao TAN GA updates --- windows/security/threat-protection/index.md | 2 +- .../windows-defender-atp/TOC.md | 1 - .../configure-microsoft-threat-experts.md | 30 ++++++++++-------- .../windows-defender-atp/get-started.md | 5 ++- .../images/MTE_applicationconfirmation.png | Bin 0 -> 7795 bytes .../windows-defender-atp/images/MTE_apply.png | Bin 0 -> 9115 bytes .../images/MTE_collaboratewithmte.png | Bin 0 -> 10826 bytes .../microsoft-threat-experts.md | 5 ++- .../windows-defender-atp/onboard.md | 1 + .../windows-defender-atp/overview.md | 3 +- .../whats-new-in-windows-defender-atp.md | 4 ++- 11 files changed, 31 insertions(+), 20 deletions(-) create mode 100644 windows/security/threat-protection/windows-defender-atp/images/MTE_applicationconfirmation.png create mode 100644 windows/security/threat-protection/windows-defender-atp/images/MTE_apply.png create mode 100644 windows/security/threat-protection/windows-defender-atp/images/MTE_collaboratewithmte.png diff --git a/windows/security/threat-protection/index.md b/windows/security/threat-protection/index.md index 4c4b362d5c..0359a92351 100644 --- a/windows/security/threat-protection/index.md +++ b/windows/security/threat-protection/index.md @@ -113,7 +113,7 @@ Windows Defender ATP's new managed threat hunting service provides proactive hun - [Targeted attack notification](windows-defender-atp/microsoft-threat-experts.md) - [Experts-on-demand](windows-defender-atp/microsoft-threat-experts.md) -- [Configure your Microsoft Threat Protection managed hunting service](windows-defender-atp/configure-microsoft-threat-experts.md) +- [Configure your Microsoft Threat Experts managed hunting service](windows-defender-atp/configure-microsoft-threat-experts.md) diff --git a/windows/security/threat-protection/windows-defender-atp/TOC.md b/windows/security/threat-protection/windows-defender-atp/TOC.md index bf7a2585b8..d3ade96a48 100644 --- a/windows/security/threat-protection/windows-defender-atp/TOC.md +++ b/windows/security/threat-protection/windows-defender-atp/TOC.md @@ -389,7 +389,6 @@ #### [Configure Windows Security app time zone settings](time-settings-windows-defender-advanced-threat-protection.md) - ## [Troubleshoot Windows Defender ATP](troubleshoot-wdatp.md) ###Troubleshoot sensor state #### [Check sensor state](check-sensor-status-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/windows-defender-atp/configure-microsoft-threat-experts.md b/windows/security/threat-protection/windows-defender-atp/configure-microsoft-threat-experts.md index 37481f2312..04731316ec 100644 --- a/windows/security/threat-protection/windows-defender-atp/configure-microsoft-threat-experts.md +++ b/windows/security/threat-protection/windows-defender-atp/configure-microsoft-threat-experts.md @@ -26,27 +26,26 @@ ms.date: 02/28/2019 [!include[Prerelease information](prerelease.md)] ## Before you begin -To experience the full Microsoft Threat Experts preview capability in Windows Defender ATP, you need to have a valid Premier customer service and support account. However, Premier charges will not be incurred during the preview. +To experience the full Microsoft Threat Experts targeted attack notification capability in Windows Defender ATP, and preview the experts-on-demand capability, you need to have a valid Premier customer service and support account. Premier charges will not be incurred during for the capability in preview, but for the generally available capability, there will be charges. You also need to ensure that you have Windows Defender ATP deployed in your environment with machines enrolled, and not just on a laboratory set-up. -## Register to Microsoft Threat Experts preview -If you're already a Windows Defender ATP customer, you can apply for preview through the Windows Defender ATP portal. +## Register to Microsoft Threat Experts managed threat hunting service +If you're already a Windows Defender ATP customer, you can apply through the Windows Defender ATP portal. -1. From the navigation pane, go to **Settings > General > Advanced features > Threat Experts**. +1. From the navigation pane, go to **Settings > General > Advanced features > Microsoft Threat Experts**. -2. Click **Apply for preview**. +2. Click **Apply**. +![Image of Microsoft Threat Experts settings](images/MTE_collaboratewithmte.png) -3. In the **Apply for preview** dialog box, read and make sure you understand the preview's terms of agreement. +3. Enter your name and email address so that Microsoft can get back to you on your application. +![Image of Microsoft Threat Experts application](images/MTE_apply.png) -4. Enter your name and email address so that Microsoft can get back to you on your application. - -5. Read the privacy statement, then click **Submit** when you're done. - - >[!NOTE] - >You will receive a welcome email once your application is approved. Then, from the navigation pane, go to **Settings** > **General** > **Advanced features** to turn the **Threat Experts** toggle on. Click **Save preferences**. +4. Read the privacy statement, then click **Submit** when you're done. You will receive a welcome email once your application is approved. +![Image of Microsoft Threat Experts application confirmation](images/MTE_applicationconfirmation.png) +6. From the navigation pane, go to **Settings** > **General** > **Advanced features** to turn the **Threat Experts** toggle on. Click **Save preferences**. ## Receive targeted attack notification from Microsoft Threat Experts You can receive targeted attack notification from Microsoft Threat Experts through the following: @@ -56,7 +55,7 @@ You can receive targeted attack notification from Microsoft Threat Experts throu To receive targeted attack notifications through email, you need to create an email notification rule. ### Create an email notification rule -You can create rules to send email notifications for notification recipients. See Configure alert notifications to create, edit, delete, or troubleshoot email notification, for details. +You can create rules to send email notifications for notification recipients. See [Configure alert notifications](configure-email-notifications-windows-defender-advanced-threat-protection.md) to create, edit, delete, or troubleshoot email notification, for details. ## View the targeted attack notification @@ -68,6 +67,9 @@ You'll start receiving targeted attack notification from Microsoft Threat Expert ## Ask a Microsoft threat expert about suspicious cybersecurity activities in your organization +>[!NOTE] +>The Microsoft Threat Experts' experts-on-demand capability is still in preview. You can only use the experts-on-demand capability if you have applied for preview and your application has been approved. + You can partner with Microsoft Threat Experts who can be engaged directly from within the Windows Defender Security Center for timely and accurate response. Experts provide insights needed to better understand complex threats, targeted attack notifications that you get, or if you need more information about the alerts, a potentially compromised machine, or a threat intelligence context that you see on your portal dashboard. 1. Navigate to the portal page with the relevant information that you'd like to investigate, for example, the **Incident** page. Ensure that the page for the relevant alert or machine is in view before raising an inquiry. @@ -115,7 +117,7 @@ You can partner with Microsoft Threat Experts who can be engaged directly from w **Threat intelligence details** - This morning, we detected a phishing email that delivered a malicious Word document to a user. This caused a series of suspicious events which triggered multiple Windows Defender alerts for [malware name] malware. Do you have any information on this malware? If yes, can you please send me a link? -- I recently saw a [social media reference e.g. Twitter or blog] post about a threat that is targeting my industry. Can you help me understand what protection WDATP provides against this threat actor? +- I recently saw a [social media reference e.g. Twitter or blog] post about a threat that is targeting my industry. Can you help me understand what protection Windows Defender ATP provides against this threat actor? **Microsoft Threat Experts’ alert communications** - Can your incident response team help us address the targeted attack notification that we got? diff --git a/windows/security/threat-protection/windows-defender-atp/get-started.md b/windows/security/threat-protection/windows-defender-atp/get-started.md index 96a02d2c87..f3b11e8133 100644 --- a/windows/security/threat-protection/windows-defender-atp/get-started.md +++ b/windows/security/threat-protection/windows-defender-atp/get-started.md @@ -49,6 +49,9 @@ In conjunction with being able to quickly respond to advanced attacks, Windows D **Secure score**
Windows Defender ATP provides a security posture capability to help you dynamically assess the security state of your enterprise network, identify unprotected systems, and take recommended actions to improve the overall security state of your network. +**Microsoft Threat Experts**
+Microsoft Threat Experts is the new managed threat hunting service in Windows Defender ATP that provides proactive hunting, prioritization, and additional context and insights that further empower security operations centers (SOCs) to identify and respond to threats quickly and accurately. It provides additional layer of expertise and optics that Microsoft customers can utilize to augment security operation capabilities as part of Microsoft 365. + **Advanced hunting**
Advanced hunting allows you to hunt for possible threats across your organization using a powerful search and query tool. You can also create custom detection rules based on the queries you created and surface alerts in Windows Defender Security Center. @@ -67,4 +70,4 @@ Topic | Description [Data storage and privacy](data-storage-privacy-windows-defender-advanced-threat-protection.md) | Explains the data storage and privacy details related to Windows Defender ATP. [Assign user access to the portal](assign-portal-access-windows-defender-advanced-threat-protection.md) | Set permissions to manage who can access the portal. You can set basic permissions or set granular permissions using role-based access control (RBAC). [Evaluate Windows Defender ATP](evaluate-atp.md) | Evaluate the various capabilities in Windows Defender ATP and test features out. -[Access the Windows Defender Security Center Community Center](community-windows-defender-advanced-threat-protection.md) | The Windows Defender ATP Community Center is a place where community members can learn, collaborate, and share experiences about the product. \ No newline at end of file +[Access the Windows Defender Security Center Community Center](community-windows-defender-advanced-threat-protection.md) | The Windows Defender ATP Community Center is a place where community members can learn, collaborate, and share experiences about the product. diff --git a/windows/security/threat-protection/windows-defender-atp/images/MTE_applicationconfirmation.png b/windows/security/threat-protection/windows-defender-atp/images/MTE_applicationconfirmation.png new file mode 100644 index 0000000000000000000000000000000000000000..2c04ad2fc80f23a15f5e158584301e54d7e62333 GIT binary patch literal 7795 zcmdUUeLR!<|Np8}O2tVxPD)Cm6qTaP%}$X}A@_|@xyjv(*(?((2?3BFjiMC z$PN9Xy6d3&?TmF+|ClbgV$NYPeke4gl-OwrOj|I(WbPB@h4v4@_@ja$+czCJ2<-AQ zyBR7Z0_}gx4+E)C?1TcV!ar8D&kfnq{TP3w4@6(AxCxxuBs=4P^2Ok8pnV{S5UFhW z=6^2kALbQw11v>D$nW2!0`o?h+2sa0*gyCdCajah^ncT`8mhie@t;r{0>g2w#-ToO$2YsJld~k zxG^$rt;e$7Eq&JbqfaSuP8vaW2WBkx+H18E6a|l5ADFox+)jP-=&r-YJzI7ee)+hc zw0=!_-Hw~pHSCW8&!2pJo5WD6)qHR`E+RM5_cXpL&!l5Pyv`TtKbmzbH)4@tT)>>` z`trr~5(M(*n;Z+V2J(LDTnPkHv6!~l^6}&S_|YI;v4!j4n<0=XUc{K{ z;s?d({jlXh#X?8zC^2R6^2kU>Cd=Ls@}41@88lll;(9_Lfg5*1?&?2~hrCxgzaDaZ zYyMiun}>F5Ag*SzTO4qNK>B~x{*PM5u#2I@fxvxss#liQ8IP|#Bofm&P5V+Jts>>j^)!ZV}qWy~`3f~(uM`JYyy zOE^wD<=1bDJMY}_X-ZrmAl~)&@-ma|OSU+a-e!4rFTGg>;h~|FHZsI`ryoqXe!{OXs)}9l`0-;)XwI%}X&5LW zMs7*p5vNUV`}woBPk?0witvcNEwZbwz^maIzwZz6YTORFd`8c)Ggxo#xhHmANnVga zIo|v<1{Im*FP)u>aGf0#RokXiNA*F74!0HN)Ny+ArIQT`KVn^+|{vHlD zAY2DeW%f}-0cX<5CY?)VD<`uVOVgx6dn;U9nb=6D*e!}CNvkss%PHt7dDh``WLFZN zlZ6Ocd6!j&I<2BQ?)pLJlz~CNJ*?3?I+~6R3HgRcMnu%mhr#$S^YT!Ugx=+jjt=4kE<79#u1+BaP-0`(xkz4$ zXhGb}%uKg7Z~F!^ozBB@>pM;NiG~vqj5Y4)UwoT z7J6BIf*9}waQZb*eGv0QuN2c5I({wJw1KN(7Mn* zZFV*kK~g^Mk6JX}Mmrx(w;5fkHSZtl7DVdIUc3jqspT1uM? zq0mX!?v_+F0Y8%AshjD8#X2=8CpBsOwxzwl|9N>-c{# zYhE&gzIpTfqo!90?hoRj2g=@T`eiNH?ZCc)NLc8Qi!du|ciY(9Q=8&K`_k60U;hZq zsrNBgPfHQa=e{svkk)>wAeFl7UaE5sE-z+KaPS(nFhhw%LPRfrJpAj%*2TpL{s?aK z=_ab~D1CyAxKdD15XEZ3;PC^M!63(fEG`$ePZcw!`3-!7D+N8j`B4XbsiFCwlf}A? zoMIjbbs8vrc2LcfwnG#}Qzf~5MIt`5D@n8^Gvw^Cd%yoKA9w$#vG1*0g|5fihlgJa z9%!RO*Xn0-3E%ISl1T3vRJoQ=_q^A89E%qjV`kA>iP7uCdRXE7)yZI&j{%0v0H=k8 z1&#DJOb&@1G)ZkM4>+x&l-eSTEuV&s)KphTM@RGYOI|X3JoWW*n4EB``wCt!=&YKO@m6ftc!%ibls}MPoo}Q~wKF=Ax2t}8b zvndB7BO{43c8CMuTkqt_e9yd`oD6i`S8*ewuFmkq7uQ^-i5S*mSc}D7|>fkIQ^ZQ=^aHGA!Ht`TNVwzpOEIC64A&A`z{Tv|m|{asI87Q0K5|L+n#a4a^y*{lA8&{vP`UV4mG!jS=*<8Z!A% zUbi5&FZ7Rlrc{`zsqP4xy>nmLALzR8c+>4$HUMW4;i7GLMt0bnjxz_5^&f ziRMZD#+|e?UfY+tm+smAlWu(Hr=2u9kkSBwO*;5P=xPt-gAa-FHe`eJP`d-UE(iGk z?$Lb7X2^{5|38j@sOt!rYlnQCfM}6@KL3Or4IBa*3+(9ft#WRsw5cRNd~p5%%eER$ zn+~{P`P%-7RiQl#k!*w-Ki||b+Qu&OJKer%D$?=r4vl@O9g~w~eF6F_RkgKepD7HhbN&YNggoY22e5u=m{ z@|6ZoK`(ur8{bJOT@Zu^&kE=UsYy1R;UbkuyHaMr-)B?2^>%|FNUaPu`x?OhB_WUx z+qOl_{vDU#9^{AB)6TGd+C7FqXf@sJ!LGIUVFu{4dA#QU7i#Xse)tpkA3!tZXi+-w z;pWYoDaK(Dap%uXiYUaSp|er2GeApGuJqOOVn4XMpxCpwzv@dzM}50}!jF>NqDDtY zhkyQbwRI!05S$7C<(-|ESw5iP+lGg|Tf`SFEQY^-uNZ^=BqRYBYA2e1tj+@*Wd*1! z(R`jls;IEkOz*+j0!&LuO%>e%FiuegNpwtCcQVQsVC61lWkd(}>(^&+f+m$prAwl< zGtkUHZ|_g!Rlo;tX*5Fd+;j^-3t{G9h$|_Tt(imFLCxTnMgtTju9%t6FMJQ*yT#r^ z%gxP=E*RnNtA=0su~?7V&D*S;ChXD~45=lBT{_M~qSLoxOXijSK}4E^aB9j5Y)z{Y zXgb;zzs!3MR;9) zk-2)$tO-`#PIB+12ja~z+7Ph*(y%uXxBu5C?z+WN4>jFD9zGbs5lt%g{h#f zo~j0$hRc{;-nJ^G2m_s>K!9&1y$_>9(K`QD4W0m<8XFt$bxb=p06H*)!EiJpPw+1n zjp7*$#>9^Wu^7QIdo2k)0oVYL$r5VrW=S4!(x^e*L^OuGv$m|Q&8pN<8!);z2IC0! zJfDFBWyoYYnIHj-Gxlu!Wq5wxQECE(4mi{6<`gDZS0o6&*rRlzgSv0B+PA7y@wV`E zfJt|Echr~~Cd-$KEl-8o0V%&%RaK^{f!ZEV#}o(a^a8=rlKw|)Q_kh$@^Bcf=28_q zNT8BruD&D&VrKD<2jB@r@6Rb%5xVXeUr^0Z3E&C0_mL+?y33o(1$YmC!ze0$M8Ox~vWMo>6~aDp}P zIi5BR50>RgrlDp$Gg&bsF>wOlE{r11fM@LcoKC__vvU0s z-0Rocl~hegJpvj%^)!&kT0m$byN5d)7*QdsO4s1x_GlS)^3Zh*h!sNLV9<4M$LRys3QC8()$KSc-~@h_PgkvF9K*pj?QG zTM(l2!7sM1xl}$hXaj|=#U3JUPv-rgmlw;mhx*1@WK z_r8M@oCTmc0X;c)fX(iidl^H96Z+@pF@aH0G@yduMn*;iZ@me;5Ui3NgEpM#Bm1WU zxEg4!@zK>=s#4m#KUW(I^+w0W5OX9Fi7fje%+z(|zKzr(9JA#zYdak6@GM>)s%L4iU80}lGutrmTxUKS>UG+9Zf6USt& zwO;-54AV*ks^EP%a&(QO~z2OdkWbjAi63y8k?P$ z$Lf92P>#>WHqM+3^B$je>?GwFwDdSrk|nz6lg{^W%c5Yj9_`VR2LWtA{{V;rAE(dG z&eG++%5ETgS6&H!i(f@bCRL~i-MjoKVR(M z^v-W~E8i81EH%`DSdy_63e}BWE3V0dv(8=2+%aLiuRcM#%0o(NF;cqVeDGguNudK)NLT%=?qpDfa<@il-V zr#V*G6!~>NvQsp9-kD3{ovY+EOLbxqX3UkHNlh{Vs;k&QObH&MC%Mm4%WX4DCM1Sy zM$v{Vo0P%S(hBI6+r~uO+i8}curESd2(T4GNM-YV|w*!ueqk8>y@}uyTqc)&cno##E=l3aP zmkG^g5#_3kfCkOP%8+k_{r`bO^8d&=zpPDwKzhmi=t!Ttr`JBuTk>gsQ6YBa^u+;kLuar9+iMA$5d z_4H%ebl)5d_Mci84!6KoD-#lyht#CCT>)I}2l97~21NoE$hYA}McA`q+q`y(upx%) zM9BbhB}8j^3Kf%n2E}VtTb+r&x7G)Vywcp#GQy)p{`erLHcr$7gQGnD$}|qi^;1`m zSrK@O?hFkL{rJv4RW3MH0bbGIKEkAnw%fKXGD*=)v9V|LVj-9=EY9}=4N%%TmKURY z^ypEj@mqF$Zn>OUz5ZEy2 z1k}OYJJ&cuT`gw0(m3LWdGun3XM1z=!`x|4=~CvhgfD%b3R`tu{n-M0l+fzp8Fff4 zYCbJjC~lC_5)zD~mgeF8BNFoxNUg)tiZ=^P!GUAG--3nFR@=1lTC>lf%*{12JFLKP z`(o<8I!bLWEJn9G560r&1W&k&b-fmBX8HlR8B1OLN0YK=tAIs{w2{u`N!`r{V7nLo zZrU6nq>0VVhl^n=rQn8+K-`XK!4?yZ@$;7E=B7*I2P0;_-J9O!04q}<@6KQQ&E_^Z z2EAIu>T=zkA8lG7phYpJlJ8YD6Z{xyRK)yv+VaTpn6&C@{l(F2ls5=m#RS!x{3b5M@{XweCxXXV>t0~a&nu@ zDFCOv#9MF0Q* literal 0 HcmV?d00001 diff --git a/windows/security/threat-protection/windows-defender-atp/images/MTE_apply.png b/windows/security/threat-protection/windows-defender-atp/images/MTE_apply.png new file mode 100644 index 0000000000000000000000000000000000000000..a7096ee4aa3c1b4f0ddd6f1d3b744bc8eb50469f GIT binary patch literal 9115 zcmch7c|4SD`}ZY#B`tT!E~Q15WXrBawvZ(nYskJcL&h@h5|t2zvW>D2W{5Gip%Mz& z8M`Eg8OAc!8OD35_kMoQ@BX~c^LwB7kN1!Ha2?liuGeuK=kfg>=hNGU+Fbkj_5%RG zrK@wp1OS*)z@IY*8z^~OKqv$MaQf;%0s!F9=e-|O(#1pkppYG^YoNtG#Ugk@RA%~8 zz`!q&)?MgT7}V9rA1Fk(>wuzzP*8NkDZtU+%@^wC;|(0+JarnB@86SO_wfz(cXM%t z0>#|z%AoYnFR8zi{hq1_)XmEYkl*0u1mAG(y)pH1h6dUDI{`MnyL;*fes%5^;OJ=& zs`>-C4;AsCm}5_DVejwl=IsJ};Gc;GW$eG(!~7kcfVJI6_Pg%7$VecEn{&xNKP~S)XA4ija(N}4SVk&DZRiD zVX@cxAo}D4hol!)e2wPX6%AWcALS2>DU!5K@zN)c#bB|d<6Jzq-R+Z3oZ-}yd|bMI zEqxzfxc)T}G0qzgs}Z-HFS~>rtr*M@$XgGVL}ZESi(Bck=cpZ9nX*&^aS4g}Kft-! zoS54O0L#(7Ou)&MdB%5g48=mbMa!lJs*AL%$>}hJw*vq}Oib*;-21jy>FLFaw)9wX zuznR3YTeg+Jboj@4~Q5f3P~kyX$ zU&SxdTjsBZpICu=0+W9=(5?c2=cla!p!tZ@f9wA*HJMM|xT50XTU=aRSBWLX#b#Ps zS{i24X=2vsTeYetFaUU1I^vy)hn=l#p;l{-bEOBpWcx4DP_^^F;Y%yImUL)R@))a!>JUCePv{@L^)_ zL54xuACnhx${G-fVyPXwV!1EMmnq_8cUM=Iq*Wyg{$e}tB@OyeC#_8RqPG@X#L0w= zj1nRep`H^=>_jfs+)+AuC4jS$nOijrxw}nFkYWbj+1`qb8S}RA^D9f1wiB8I-SX6v zr@lj__Kz-KzFZMZozY3z2XI`y6{!z{Ve6?Giv_v4T4@Si&!9>`gvdK}YXz_2oR{Z} z+y{ywsY(HPBO-)VWQc?qZlR}}yF>*wffWAu;n09J zGc%k0lU;}d@rX&}&<$9XoSd91b>>^mTwdB4UED-?Z4|dK8aEDaTfEH9E!5YOs}G}o zQ}mc_O|q=^&+X~$U7O90ryYDfFkqgPlHxH~YHwNT`NkY=UC1lz?Ar9~IMd?6w98J< z_IAK)L;(r2u(0qLu5eQubO)Y<8Sf~ic#TxLZ7xmL?5vO2bQ+|}>H0M6R8sI8w#c^a z8O4U~VXTLw@Fj6c$^O&vs_%|pG%u*A=)1fNin0FFdTrF)+*~~)BZ74J@`16y5wG_{ zp0?z#9UTKXx-Tn0L&Jo8&G_@!*N}E5k;HejcBdWMTB@8|;&ioJZ{FO8KbhZ;EU2gW z1-=d5Gg0WuPhHIP3YCiAr=57Q&fUXfXMl)F2FJ{yh1TN((6ii&=8DNmv11FfA&7-m6aHSsszs84iB$KH!x@%7HmMm zG3=y?jZFz?L|dxI+}zx{!7qVz>pk1H_F8irmd)z_<1=Thpo+qGRoqx$nr-N^*3d%W zkf%b470xhdA}nZ-yf5Ox(WFU}J9l#TOpG#GtuCFX-=i;$&)JwjOkA`+B&0e^< zDgnP$U7p|--w!TyaJAr?`o1Yn2$Y(qeaiz^<q&L9MUK>So~V4bl_} z>*}m|d3i10-+yYM0>)0u8fYPC)_1_Spxvvjd^wFODd~Uj)OHOO-1_PQI9p@T<0km` z10o4GY;c2>UL$=yJ@1|#JI9vZ>0DlzlXJtW(z7fy^FC;qe6r5ZGeam!8LGi1;2?X( zk}LuFL47W&p8_=u3Tx z+|D6*>BNns*@Y}%v#6|mImDk|U#7}9-uyyliFj}VHs(;~x!TY%r8`GD7^G$LV8L~E^4ciEvmb?2FX}5ziT2yh{9s@fec*cv-Z%wX{oXS{iX}q2 zj9*G^=i=9r+J!ik87MLkUP)N1GKA3vdJx@j<9AUZW5kV$?B*WWMxSh(5o32)tP$Znh8;<5Ezc$uFG@gCC7961t-kfUWV#+$hY z&<1u`+Q`kIb>(kcA2mo_Er|Y5oVN)ALvG~OKrN0TkgcutxsA$vG=*p?-xc!8ok!C4 zLeU*kb{k&HVe^V4D<`K^Wf;mS6YF8SZrPcxLYY-Q(LqKcLrtXXmg+W^`Lhf*;CY4_ zs6uY_pF1_tD{$K2xn#%B*%_tb4XVQ%(B7@o~~-wj}JRYspx3={)_`BBv$a&U%Y7E zK?B7@8FUTOcwCBY$*OIBi+>WPz7L-s50hX}!p3^tQ7R1$KiM<9KDsY@lD9u5E(Uda zK=K#eC<{{7rCnITQ;XcfYwelxMRY8+c7oZ{@dJz{+{UFdwO>s#-Rlrhp2O@>d>|Yy zV2Nvb={PbPe{N%EV=6zT+V+vK2ELg7dfu{wS_Qqu-IeE}X4|555|d9<=Ukyht<$GJ zc9wk)L9n9Kx)}SzCDs{u5qLFG*9=*`SuB&@{#V<@o>LZg$PRd~_;g?oGCJ?{o?I9g@iJXDJc$-uwJRKH8DA72}; zUS#H08*UcCc))4*oPy^EGQGI(7cBH6w1}10~651hY8l!xOZSHl`Rd0 z=Tl!Ls}B;fe`2FG4mq+y;9FQE8MHr3OFzBDiuuBlu?AoJD(6)mvyJ8DC7yX!1pNal zdgSC!7?;=BTaMdyS$wL5v6!h#gOzgW%IGcA{6O4%pnzT>Jdm-^pyV#f$;gZAHPhuSvm}jvXwvzFxb<;Q=`DQ)QpTRP>2f z9ffyDv?lld>SQX@?#lkBc*BXiHMiP!7jWXGx^W{MyCGdoGqHRnsEm-ty9ra$S9E*g z_>xL!$@|aN3#@0DN2@b#*qyXFJY%wx%RVw_f$_Mq_Sp2g@IYFItcmm{o{l!2p!dhX zHz%XleqieJA3kL)_E?2%I!+&K8yM`9+x3cqHVY4vd6$CTMmN~K<)~}8rg0*J?%{5m zX}j>zgP##{bv1_MEi>f_arf~u&!AqLj8m4!RjM!&mtI${cOp#mJ<>e7D+dA?wUT^% zYtJZ78xPQH*dx-QEWi1Vmc`VPj|&1msz zSj|lPo9sDU@@%valG|VKw0mE(A|n67OC(26o?;tWsN^`y#R~~lXz&F4j zNJLR>51&3tZr6gqgNGViJGd!bJp<;s`P>7$+c-tZojm=E0{LIcXF3)r)Ok`gV)kQU zy;1DBa4m#|QXdSC|DHC{mxAU!eoZkNE7Yc}21af7t?Q|@EJwjpgmI^zOGT?#G>sDW zy(pqhaJF+o(>r@Rr+i zTZ24|maw_GD}Mmr56ezf-;I=Iiz4v!RL72VSvb0}@CIC4k!4)x=&f6Im_N_}S3blF zY#vq-es|EN?qDt{ivOJJ$ojPSo6X1p#+FfPD7hp~aY9`{|8&>uW0~nw8tKU!isLo$ zxs&=n&Gkz~6U{f6UT`=N+nc-&9*q7lb*A0wim8iXII2+@)eu@Wv0@Q)Wg)WNtDUo@ z;7t-!=Si>&Yq3RHV53Yf^o^o>MVYcS&AkE8(J>a3N-jI~N$A`u{l+M}LY&5V24F?fMFcR*zFa}e$%kTr3sT?WW9`Y*`r7Y2$&E=x=vRSb$@0z{wvCwRMC zrM-+Bb52aFh6Q+{dq7#`QRn^Jw;spz?W%A94mM{Pm-4L+0{7CztQEXRPyWL5pN~p` zd1TCAIRD7$n>SF008N3()IDzCFYNwLoWM=3-|s;@{u}*E*?-!@N|tyyHcnWBBJZ_E z>L14W*s-AYMQpyhG%2bJqLAV00GFILAfhVe_M}7kP~YHS0k`_5NKY=HX&qCI8C{I6 ztW=2QS2V<8v8k8rA5Lu922URcA9VfG7bGkzbP_9kCe#(Q(P=D1|!&@E7uoBh^c3F!Au{dRpjcufWrnyN$pyRXK%gE8XdI;lj0%bY8ZX} zt8=;A@{cCVx(8)FJw26S@kj`;@NK#rFS=sc0goK&7`3XgC;7JH)zvPVfXqDeEJ_Oe(h5DAJNdA&=8r=ec zK-6qI6HaSaz}MW{0wg6R)x5a@hpV5W+9ElRL04yu@pMY9p1yv7S_24ObMx}t!Q~|8 zfB??Iz`#JwHvXG)uOx1?XT+aLB=5|9-0R+0#qsmCV-!+zq5#1RT|*KlOl51wuUGBV z)v1CA5Q!{dig=J*>H;pz|ECTJ2tgqsfMAEfySuwv2R)jenXyDyM`o9n-Ug=wCzs%? zJF6$c*nnm6!qU>x-mNT<+c|#xctY{HEW*pgimYQF0q<4Y5Q$+pM z|A{90ZE8FLcDpNZ6O$Z$0AM*{I{C?>0nqf!+OyvOfO7iRFhoW^vkl}pL~Zr~pK~4` z;8`cr9K@}27!y~4!(`FrXr;fAWdGd}{)T@XD931OJ$+eNt4h?)4=s#tVc{crDn&_8 zwhE1NSMTZ@vNKJkcjDbE3>rqN?i|x|zMvwT?gkv@eR@PH(Zp1C70Zebd&zy(xzhO? z!_p4J3cTa{HG!iu?P66iw8oJJ!i)4t+Mu@uy(y;k8~xo`9-AqWN!#9kMl~O0=m~KA zd;BoA!o%{4jXh&{>2=^8!?=lQiQZJcRiyBIcW&H)ny&Go{xL$HBEf5*no7ji0%OCx zm+rmDGfX3lVNba70W1lZCjA+qF#`=N&j{3HMW`-Uekzpskd?1%Ew8S+q-nXT@G5_0 zf5BVb)(+3!G~xN4oUbvjQZCNv;B66$%<^($S@SP0?(d4yrVH=nnqzktG3qJhhA%th zk=>DLJXePMw00&J7Wfn=y$N+A6O2dR84PZ|EQKBK&gj%|x~R6RKp|m9AM?>L*b;Br$WU(ryoCPU zz=^1g`O1>Y2K?!VyK7WYITv6vqkMhSaShq$�?b@GoD3v_S+lemvOhwwr%zKz*fT zR`^KD^g5x=-M!0-ACX^)Mk*GMWJR47Zes=eIi>SjmIuMJnkxj|`We^P6-KvS2rG1b z{ywTw32mIiZY!6gaJg5`MXzwcJJ_b5N1DW!_H7~6Fv~5IZB{tXC=lkOv`Eu?nbYq1 zEyEXYJM{A|;tRMc7Tw2>A7^y1J2^R_3JRXwS7R!Hl;1qSBlR503mi73k@4jP1z*-= z|1Z4+@+r6Q=^`BfRx`z{0~dz>nMzKUM%VdHUdthI4E=A16yeaXYR^8k~+T+pR!1O@Jz`e0l?=Ydx_S+qMZM=|NmmX_naC$3l9ma3;gD`W%o$& zuOD5WM(SJA+8Rg=B&)i-oP&A;@9E876+U&oYq5mw7O}5wz9VmU9*gCZn*HK*p%ssc zpNWsWTW~}ZS(;w`oKIfd1hy%+J0Lw9oBvF5_r$B2**7T~W-l8aqYVktyE4rWr|%X~ z5Z!1ha;KbU7(!>4!lZhU* zZL5aw3Jus0?`y_!nGyl%VQb>5bW%MDTpM%Y4*u*aB>NhFDx2+SxFznn=W>MZgB44AA>~{qwos%*=QbpqN zv!95%;^$vLZz%_$Z48K)SDQ_n;&|h*B#Xq$CYR;L10M(WW%Q4Jh3F-nvFQ<_Pe4bw zPQNPbT>YN<2tG?$Mk|_XFQs=q{|afHhdUa4)#>FoI<7;z#jS3Yzd^b=H?yxWv^}YY zh->LPqcrYWJDh23@*VP?9Q$A{s3j*=)`yqSh72TL?Z(A9}7~Xys`jLauLRloTtB%DVSFeu2B>TR*>s*~h7R zca|4A?`o`yS2mEd9nWl%5eP<32^~X}!ab*kmAF!{*P)fw2HJ*DHNW|XamcM(O_dUb zO1is@L6|opS7pY?kYqOXloH&aJ~Xthxf4y_w(BSj>=dlclJ!EWToHHrPU91GXqz_A4L931<1QYsup!YQ<>>Zn`yobdLSGiFT)Qh(CN)jP+}YZutc^qb zTH#!cqT9nO0ns%zMRfumT)}Cy8Ux_zDO7FK^G*LKWvL1>UL&*rO=YKiWANFE1}$ET zoH@d7{$f!6U}-&wCT^-507A5W;>GSMqC79?)r%re`}UH`nZ!yU8BL;=Dd zCTwD4I`t+wX+p@{vHU*2Uv=`>u9oD^v>nVP!b2)%iFMVAF#oli^VYeCaJ~s__g~OoAEXUya&sRD~bCL98k&NZf$J^%REQE z!X1nVE?(hPIbFMN4ghB&Ks-z6(SvAvhu11}O6If~nTkgeWIr*&}(GUQ*=FFMWeoIOptii?qC$Qxo!T4{fT?{JW zyp@&JX`5@KVBsbn$_X6haQQzM7yo^vuPUHZ0k;zr4Emb^pB1f+c!q(k`ASvx*m1%z$M^GP8D}bbMs9Y6navPI$HuF zD_4;GN4F3=GE4&k%A*eQ9{q>{KBR+cA0M&nCmJHvOTgk729t>aYZ8-<(ei=wcc-VP zbrUOnCeSl8&iVip3UvjWE5k^yEO4m-;b5KRdi0^f?Ck5Owd4BwE$k#~$M!UHb8-r* zs_wpd^ClUspsO6ZSxVk*jOMl)H~^HLr%2DbI6Jq3)eLY!BRC&IM}|s>oOgSnY5uFs zOmvxJi+fkrRj}HH!eDUi0qgS+Fsr|yre@O;FC1iJ!K((Zkg~240kK3srNB5_4!-KD zYhq{^*BmD}QqIL1asKEAi1}DqSwYZb3}Pa~4CUN~5ghsR(_{A7gqJU~WgMH&OG_I~ zwZx~K$xsStz8oJ=Lp^w2R@QWDYiqBlVq#*_H$G13_Xb;|tA6a)HPO?1<^choIB|mc z@|3}LGrv!tMFZ`Q?n>~9BRc;6LEH|YYG-h|jW;vf!6i#)Z~^uuAYg)gij3)fa^&>h z!oYpe?Mbq*y`Y<1+oG(jT$dbxkQyx)0^S50YXZPN%e}h*I&yx9s}1$_w&x7fZ^Pj= zCZ?t^a0lcS6)&DUr=2M0`(2X|3XahQ0=!V$mrCH50HGpSj-Rg?_)#a~qvzpK1PZRv zwz+^Cu>%-{KxgIf)YN9O&9k8&q&Ab^WP}rMqMDBWf{pK)BgpS_codKx&`HL4#!5aGK zXLDa|tT|$dl7qlKOJm~%G7%h?30T$mx1i-87XbF0Lq=We5U~8`ul(mvU?f-lC z`x}k$H}v$6iTwXm120B&s4V`bI>2nw&(H67HmP5A-`V-*KQSQsRcFM+{>nProKpNm znSog~{nRs{Is8&9i)@QvV*Y)7;uk-7vxWoE44oAHi$59NW&iR`;_TLv%v10V3ZScH LcmsXy-oyU|tAu!? literal 0 HcmV?d00001 diff --git a/windows/security/threat-protection/windows-defender-atp/images/MTE_collaboratewithmte.png b/windows/security/threat-protection/windows-defender-atp/images/MTE_collaboratewithmte.png new file mode 100644 index 0000000000000000000000000000000000000000..862c5ffbd7d2f21196ca8646733e66490ddca672 GIT binary patch literal 10826 zcmcI~cT|(v*Dhn5K~ctvih!et3JNMsK|lp5(rf6bNQVTeLP)TTprgRh1q4(&p-2r7 z0y+ptmy#egFi1;)NJ}IkaQ8dEd)K=6`|G=F&9@f%CMPH7?6b?WpS^RQ8yRTr-g$H< zA0OXt9c>L0KEACec%Agi4*0*}^M^cm@Ox`p`SS7Y`GoxYDPC%iFbw|er=x%K=ZS41 zhs3vH$xpxhGj!9^@4COAE5?T}uc%!ch6MazNW;n3(Z|i(&kcj-+t2^oNf_UWjH_e3 zgM8dvT>bb81lyHhbk9GdK2CR#smJ}?yqx&t*@FD=2|x0QDaP3^@Q#lYpPlz6GJV%S zi@W(cdftJlK77Ov{-6cTH>(CDU2tW%?1P3oH6ZH_24{X5zh;m^(j#n0!r*YTbxh_#S%v^zk6_;=ys(&56&^C-=wiLEcu; z&CJX!H*=;D!}49d=Di(xiXN}pf;Eq*LA}uQ?m-*mo(fWGGT8QfE>Z(r6&Ye5Iu?>q} zT|D$6ufE>l(Y51_oVz8jI2_Km<+X2Y?&R`XoVK{Q&Xp@yTHD&nmLz`tCB#1bLjJu= zc^ez}Q?WX`1qF3u*75bQkc9qGIOszuFOwap@I4|uqhzdn=thVN>#L*WxpRIY>DuDu z9{tiH$^m*b4wdNFtFJh#rN)Wg_xyL!;F;eJ3JDn+wQBv*JTXWLEFKMJoR5!>&&$r% z^quZBKmM!sk;|g0A(jyl5wKX_moI8E>|8jdHX_cvskEYOk853;$9sC z#@NRvoUtc@<#=8&uL-jr)|swWEaVVkteYrJu?rlLzq^*Dn@GpfxM?6dYknxFs7P9c zx6&IUy=t4PinCTxQGvs!>v9ZVUw)gNEpgtuTsx443v6|Q4Z#rQ=nMKZ#uSzGkSh8kcR5%Bg0Gfj{*Z>m0FN!=ILgpeNz$V~ z5mfzC{OOI~bYi-uP0{G0u<&pZ^1&xho*X@PEKYp;lk1>^vq^fA(b}J%L zsMA6+_T`n)iHSMG!?qqaTeofnpDL|1H!`|CPXMO@6~!F*Wt*H+>j96{{ihAIV=C4g zUkFh~Mhcgwy9hZsT5D@-k)m&rZ`Ye<>lx$mb^foXET4RQ6QY_fZCiEWgi1q01BhUD z{MRpIV{bqzc~}e%p{2CEyj;k8bqDAC<84bU_^zv*dlr#MM1f!@gWv1n4<0;trAO)N z)q>Gc`{s*a@!h+3=e>Dz4NQlxrybqlP9u&R48@%_1qlm8_&IALL7au+V#jyJ^PRT~b17mrng77_Or5O5tRbyD*A_H3bQVvkf6=X--7g+j@S ziP^WhvSO(?qPDRZMd|I$2p0|3eru$ij_2edwq>ybK>iW$hTWXO{<`cawGGQ~K`{#* zo#&Av%Gub3YAx_?cQ?0gsp8squU{X7fIM$oWd!r8AXE=TXs!xweiu{ZR)XclAO$lEt|90}WB}ef-VJdI68FT}uyHdTx(jbCS9iGFQ^<*LI$G=Fp2-%q9yX zj~TsMK_u$NC}2hl9zFVr$D?hMJ5!ZU*VBr@t^_0`r`o%tPin2u3B~mGB-vZy`y|hv z?dGg94uarao9kUl`1PttF}0$|$UP(A!r)jGBn0_TE#tU}e&T8MSEPnJQtY9WY?YHVx-Nhn-qeeo6FDc8~3pg%M- zs7hc2*xB^>uSO_TBK}8%nES$THD^L?!|~KUe!#bOdJBDSt`AkWbdb{5cjmAFeOhg^ zdNgENUxhQ1VO{PT-I=CBup6IQ`8Ml_0Q#ITL zQha*4T6Qh}jwed~^f>X^B$qVAKLX|lv(h)$rzNGNVrk6&wdHC5rEfaCQ6?|Vx$|{i zZS7Sa*dTSPJt+f&W7z!Bcz3YcH)j;j^)g4H7=3xB96G8#e`(1lRmuMrfbl>05-@MA z@?-4DAQ6*(NZK|Ry!*6MFoZY6_M1feU?h7iae4Wpj7Ddo_O zWs-9e5)SF7tBy$K$hvgSbZd!GIuvQ=(z|kaTsA|f{>Rfg-aLkoo2$)bGy6*%n^%yH zTI0?lo0{$@0K0#9px-*y`njvCKjxIK-}kZWBlnv{T3cF-#rJhL2&$a}uh$m8d!E7O z7V4Z(Qc?oA&!G@d9ssT}nScL%clVw>^qKCAn#Cqzf9^a{>cGy~vM$x$@rLl#NtsY9 zA`MT<)NR;}DzeQ}9DSh99>o^#+_g*o^5tBO6K@|s-h$&X98ds!2oQjC!2|s&ptgj(J zgZLzAp+;9-UHz!2sKx#JC5Z1Cs`1S5^$xPm?Vn$b0sznU<}k*?#Vmq?s>Q9YQ+F#4 zzd0ynF;hq!HGxB<29D+lqpLn9?=E@w?uHbq$jsO{+PNb+OL?J6T`Nk|9Ckes{p`lu zKkI%p%Ct@|=fSki4d!N%q3W6jWFLT%o#72N^OZvdza=}HL>QgP{Ohk99jVIwbn_JD zz#@wR%eS|^O;A{{oNboGyj^w>dlt??eYEvwzqzj$?P?zwBiVhp+IN-Uz>}N|p0dk? z%+vAuN-t-a$+ltcg_ouvgg{3Zpn^^CuwB9eR~~J2qYdPCk0pq34#(|I``~A z^<<^6fX;wa3~>2Ah!Z~=j-6LkW!W4hW=Kjql1=UHbzHRtc$50GR5teHYqikP#WldC z0ziz8Bw4NM>T2tHJlWmdeWg>G>B?Rh;dBPpWq^O%Re4{>;cynmg`%2~L@A7^HU4

E)3a z>Fr$rM355oS_6CZk~=WZA?X&{ldS_sgK}zWYF45)e?&>1Ib&pQPH_@Jbn|EDH%`UK zW{jT1!KmiK5BD1XI0(2N2c|hs9KNgn=63L-cBSVUH-G`{I&=;(>MFP*{jaCHICEuP z2);1@86f;DWMcgCn)5R=HJD^}+8)uXxx0jUU2iRj^{DPt)3Q1i|CJKTZH0}q`@9*#50%7sd z3%qim%msWfU5D^da1Hw51_*BCvBCSlNVCaysEq+}=j@)ag zMgi#%_#^|uSyy?#b#8z4wzTw8>eV0)3fSi-bWGjj~=>GOO38yY|;HcU9DbB0tVc_bJvrGX_bvcQL3EJ7hhrk?>U_Q`Xa!A`BAbBYy$)c z32b#il}x}~h?(g$tO0OF7?-jr_yRek09@B=xXPFm$fWvqspLR-01zR?OtM;N9U%Jf z-0V4NX=-b{)GC-RKO;jOc;Q)>UFF3dF4@7vdPO8r8C20gQbCk)BujJ8g8x_B5q~U zdC1bp=naUS=zzD<*Vl)lAz1}miLU1b@P_JnDSwT>N0V1AfD8Nk`MLHN*#-ao{B&G; zdhrmNq%T8WiFwzZ3s{mM<4^?14McyIh-VP{AT)7Y7Q#pp#5_xO=aW1_BKe{`~{gxS0er+MxWI6blFtR3Cz61SAu?B(jJ-Eyxd znhFYm`9S?F-JUhx1^1<5>{i)qslx(FmC8^c04y`?GRMd7c$7v!9{W%ENw zi9J$opO`*L6BijN4?7Dmt=$DkvHbS!Z%7>lg#r|o33x6s)COu9z;>jd{Z=?YoPB#~ z4bwV2*NlJdZ1EXR2Q?IIYBTA+iIYLRxE7+jVAHTQO-eSTtrMp{XWumPVIu5*&{N=*OMpv$PsEl1O`}4>y=T|zHds^b` zdwb*mP^PsD?o6?7f1L(6i|oHPP_HXgi?kfmkZA{;osup+wLc@yEhMFHDTuP$WluGogWQ4rXLJpZ+hg@nI%g+IfBLZw=7 zLS0g3T}&q1Ra8_^X#hIz9v*E~_P)MlmFSV+f!Wl8vIzCRM8_f{w9^`_PO9x`E{6)n$`TO&WP#t)B-x4Zsy>i*4^U$xpMw)KAe+4}hf1?#U(;;p^B3e#{bE6CUpZe$K8 z`00(easC1Z3pEd_gCYs2%K4ydg{`Pa?w|<@mE+H#;)=Y=NnW2>N(pD@XNyu2+i+1qH9aV_&p*ny_ri-~ZZ`pO<&!zNviLZN5>d^XK)~4qS#b0cmpopYKYZ zYi0m**q+##o!`a87x-pN1K2c(?!vx=v!S z>#*UyIR>e|xUkS%Uq2!_Ik~{AzrSB<-*d~hS2>!_%0S?OA(W~TnY6mv)LE61P!tI6 zec5w+)>O+T;7VayLZJ;YzpSh`nhM>Wy+O(Js(HXGi$d!xVES5C;68a!x)Ur4eU6oJ z&nA-A^^__xH1uTpSySJFFjD(mb6oyallXXLF?8LUGw#QDIF;s@XNYFuYT8^V`R2&} zJ%6iKCMO@2QX5(Q5aLp72#eHB^w+2lRh33d@CR z$KA`TVne}DRlm#O@-Yh!55h@9B5W>F#;r10Ekf}BXvD1;Fn^)bCCXE?Ij*lvdPlXy zSwe_TMToBMi-Vt1*5w(bsG$*qul0)4K2SbZ)RBu`@t}=iH65?gl@&ed>_A&_*2*yU z4+zLUx1W8*Lk-Vf%vMsxCQ}BW+&51+jERVb0v(u*NGCHNoQo%Cu6lhpzzTV0z)g_AfwlAzkimD`Es@J`BtNi|i zCgCbjdGK4%YTv-XY?XwriMsj|=nt8hnr0vd+sMk#(aa7`%U98%C{zvY;nvM@18Ig| zd(oSt-%?1!bJH`fleeoFY1QHHF|s4oC%)*ru^hvo?G^nh2U`H3GA#%<9)@jDP~iX z=KMgJmQAH+$zu_2OD~nGaNgsCx7B^H8S(qWEM^47jBG z7bMdEMmNbZY4x=3Kb=~;=ydmr^77om!j9H1_3%AskL`&v*-~G3=9Qx-2GbAKZXr`y zSy@ZqV_D(=wa~`g!J!zC#Ky64e$C^hg@wdSJbvV4vYX{?g*l-d00BZl1ftoI3m-Fi z+4;4#woXn?ks%lS>uPES-M5t;Ipivh?JHppD}i98rs>7?Fd+vUXIF$s@+B*(MJRpwp*DB~v@?M%!Aw;C52z)RvTv>ID6| zOq)^9q1quADh3*@(A*XIXexJ9#CQ}4iiNO?;H8c$-$sc?@}ueRTri1xoELxmQ6Q&r zBHB1ST2#r;^%JKpQHIF6qh`-u^ctz5?ET_$^lz0kT$VCsc&$8i6R$NC3j7kRj8Jj{ zs<<*i-m5&Xcz~J&L}9Ps#nL;P=&zVtFSW(r<>yOkDW?`~q=cWz8`LCu7P-y7q;3o* z`FPWAr-XYu)4(K11190TO&^t-?J7sFl1^f`>f!q-lq={jka{YB&UlCcd5WyLjUmlt zNNWxmfcY~FA|_MGot*~Iwt1P$cFwKkzIDuJxFPuOl|z`G;vL0SXL<;~G@I7Q=jG^< z?4Y%rQLE2s-|UT7mq;oq)-*Sd-y@>*?ZGRl7AR6Wc^Tu2qeQU>bCcJ&E*t#=+J%|Vw7wvOClMMRH0 zbG;f5uB7DzaE7?S=B%p;)#<|#7*q5nAJ5+iOJS(-Y zaF1UN4LsV`+6q$(ul3qv+83kb=Tj8CdH_Qp3+~a%umoIy){IA2n##%Gy@0v}JfzK^ zpWm8~I)DCrj{!kMAh7v18AiTjM>E)zttY%lD*_{8? zV|xhY<$cznYfF>VHK$Ht?i$LQooj zO4i-3W++Rb2~Ie6>dI0NKE%t*3(;6XdLHVB4|~!+uza~`MdN6+wnkgRdEaxrpjx9d z_a@nvbUn~`rqqxy(a$T{FYo1CXt51Z+DSxCF_u-UU9q`X8Jm$s=^V}+V)Qpf2%Fp4 z&3{eg_nx1dr$XlvTBDTFQS?aM5ZlV!JPSIb%`{D@!!jKb&7lQ&@OV^ZD){#4^pGA- zXF=j_>`05|-n zbnw3>NTMRmcS2{B)3{nEO{?t%h01Pv+>t#U?xj84C=JYrsEn`_$u{3zpcP(Zu$jzG+@h@kAirzYeKN6BYbtn?@D zRFSM@-MqZ~{R(gSc+$?u$Pg=sC=@68Gl)WGWhO<_$AS&q@_nN42GfFZ=_C?YCTd=0!D6W)=OMm;uOE z^QuZ_UsC6z?Ck8ls{?W$25K8vPz||rS@Z6$u7{W3KkTO8$Pdwp7sV!JD)$dhzmL1( z&?IF}Cg#XfN?vBERzC1+ltm)51|On-bn3> zf_ot=Xb#_YRvLAcQ+k({NlHtMkB2s$zQxFUHZ^M~GOs>yXezRzUph-QzGnWtWCTpZJ897 zQ$PfVKwZz} z-03*wt`VWy2w_F{iKYmEPT!Z^q8?WIzxy!*vX0h_P4ZEWxfNLCv|QfF;5Q!r>0SR&po2JxL@FD_=l_;8ktBgFUl-}BYYHBH zRoPZMblW9NzB*#k`OAiAIPS8IgmX23zi~J@@{mSEfTNS*Xuu^qZi-hhAbU0$%eE$a zW!SOjr%BaoVr_b^thA-UL2HJy%1A)_MvqGEVzSDaXBsEm#4McirycnZ47blb@9gZn zsP?8pc>beRzR&mIsVi8S*UH+p!`$YQ!-iN7hvvhGX4}8pVb>nq?;3Bs=pZFA`ThgY zMJU%_9)95=85?wG6#qy;rpIMpgl3_T)2WD=oeKaUbNzKAlWmDnKSo~?4Ew*=q<s%mn76(l;fC0LQ~ zH>Igy3nnU}7Kwt2Rj*59YC973=2RlkP=@*nF!bWp21c)D^?<_y_G>Vxg~G3NVt@a-TvJzv|8zmY&C|aLUwiZBP3pyS zmhZ1cYk#W2%PT4>M|Rbvk=Q+UoAbdj{cJ#=yCAN5Eq;`!_P zcPKC-S#?F+!*kQ5BPOrrm6ZW0B5QX&y`dDiFq}K2Gw626qtnk-Go{zzApx z13Z^kx`ow8#&fS{99f_Z3?wN$6Dv$h8Mk1iU;+oCSjXGT%UFTqrTQeC@WPTpPyCa9 zz3Q4LpY+&K_Hm5Ka^kr6SL3d^{nxaUn094OJ%8h0T^PkiF4{Y`KcRXwW-_W{q*D(# zPhDmg+?~SeoOLm4{j?384W;+1#DoN;F!uo$8U$rom|Rv0uH6fgELE^7dyqz_5GY^1 z++O8Wgt8^R#IE-Fe-alf>Os?7-2k^xf{G&+~s%);MzsX5w?-6FYi*bOOXSp_kPI2xEU+$ z_;Mtng#?McT=4@?93v=U9a$HMz|ow;6v|S8x-}c6`^^{I<$F|;QD26?*I>zdbzd2e zc_D#0BOwV3wfBi45_TD0%{cTRjd*d|3JMCS$z%2$C7Q{M8Hzv;Z0})fijLw}Y zL*&5Aj*y%gPlfFNj0>Ln2zl@&`>1c>;(4pmdtcY@fBPK$TyNJyepb+W?keS3NOgez zC&6m_Ju>)pTxm^0)V$C4lVhV*gQ3qh+}%>Vb#C5#y1J=z<=n4u1)@VheSFI4ZiLg1 zFBP5bW7@anRhvbu6DeIsj2S>O(U6q zyC(NH=X=fT4~U8C#9}#i6xT$s2>qYl%)_=%@2?>}n(v4IXReL>H!rPR^M1E~Y>FFu za)0XY1nPITl!Ov;MdpM5i?o0BR?Aq8KvCLelaSmxZ)fTndhOuAMtEqsb_1=r>ckLo zYwE%kyTp%_(F3WYdAQx`DcULVuCgjT;bnl+CosZP;uatR<*_>*B zZmBvNzo-=CZUgQuU3d{&8Bz8Y-whTZFHYFpPWkATx%*`p(P5rS=_lM zmU^T|MS0USb>t#kt~kdt@3_iigxdDS9ji}BJdg`ZY_5gEj~<4Gmn+ScPHNS!i#fTg zDQDVj($xyOxR3 z=jUkgLcwr3!i6{K>!s7J$BrY1ge2kye{(xQnWH zZG^&OsGByMWis=sn;7wY!;FiC$qr|9c830Di1E*M5JeWF%+>@?ORhh?it}^UR(rsG zy*ePGIOQ=>dL-DHGPjqhcf=t%DR#;CWbex-*wBHD9Ok*6W!jI&JAKzV%L%fMhF6hO z>&(~i7j3Mh-90$3(_g?KzAZD^uU7U ziqf;e8^R7>);4}m`_U?(b4yr`7u0ryM;vl-Z7BQ=1aj?5lZNH_P&o{Vs+!OiIi0+% zZ@_}*WzHH=5_cAMS*tGevYF%qf5M9W86?&F1bd0nn`OR;`yu|+vqRtc?u*G& z+Xq+e`x-Kke(eP-Tg8tQ*WNVRTD`Jn2rD%`O;($R&BTO#?Tvm0YF(EDNT z2MPlYC(+9B)}~CFR@7!*Q{z3H?ME(Nc^v#mIarBph@ihXwOYJ+-?(&ru9 z`TwBW3-K2A>HX+Z;pCP&g{G{8(?-N^r[!NOTE] +>The Microsoft Threat Experts' experts-on-demand capability is still in preview. You can only use the experts-on-demand capability if you have applied for preview and your application has been approved. + Customers can engage our security experts directly from within Windows Defender Security Center for timely and accurate response. Experts provide insights needed to better understand the complex threats affecting your organization, from alert inquiries, potentially compromised machines, root cause of a suspicious network connection, to additional threat intelligence regarding ongoing advanced persistent threat campaigns. With this capability, you can: - Get additional clarification on alerts including root cause or scope of the incident - Gain clarity into suspicious machine behavior and next steps if faced with an advanced attacker @@ -44,4 +47,4 @@ Customers can engage our security experts directly from within Windows Defender ## Related topic -- [Configure Microsoft Threat Experts capabilities](configure-microsoft-threat-experts.md) \ No newline at end of file +- [Configure Microsoft Threat Experts capabilities](configure-microsoft-threat-experts.md) diff --git a/windows/security/threat-protection/windows-defender-atp/onboard.md b/windows/security/threat-protection/windows-defender-atp/onboard.md index 979917a18f..33c43ec774 100644 --- a/windows/security/threat-protection/windows-defender-atp/onboard.md +++ b/windows/security/threat-protection/windows-defender-atp/onboard.md @@ -31,6 +31,7 @@ Topic | Description [Configure attack surface reduction capabilities](configure-attack-surface-reduction.md) | By ensuring configuration settings are properly set and exploit mitigation techniques are applied, these set of capabilities resist attacks and exploitations. [Configure next generation protection](../windows-defender-antivirus/configure-windows-defender-antivirus-features.md) | Configure next generation protection to catch all types of emerging threats. [Configure Secure score dashboard security controls](secure-score-dashboard-windows-defender-advanced-threat-protection.md) | Configure the security controls in Secure score to increase the security posture of your organization. +[Configure Microsoft Threat Experts capabilities](configure-microsoft-threat-experts.md) | Configure and manage how you would like to get cybersecurity threat intelligence from Microsoft Threat Experts. Configure Microsoft Threat Protection integration| Configure other solutions that integrate with Windows Defender ATP. Management and API support| Pull alerts to your SIEM or use APIs to create custom alerts. Create and build Power BI reports. [Configure Windows Defender Security Center settings](preferences-setup-windows-defender-advanced-threat-protection.md) | Configure portal related settings such as general settings, advanced features, enable the preview experience and others. diff --git a/windows/security/threat-protection/windows-defender-atp/overview.md b/windows/security/threat-protection/windows-defender-atp/overview.md index f91e35c7df..d2421506b2 100644 --- a/windows/security/threat-protection/windows-defender-atp/overview.md +++ b/windows/security/threat-protection/windows-defender-atp/overview.md @@ -38,9 +38,10 @@ Topic | Description [Endpoint detection and response](overview-endpoint-detection-response.md) | Understand how Windows Defender ATP continuously monitors your organization for possible attacks against systems, networks, or users in your organization and the features you can use to mitigate and remediate threats. [Automated investigation and remediation](automated-investigations-windows-defender-advanced-threat-protection.md) | In conjunction with being able to quickly respond to advanced attacks, Windows Defender ATP offers automatic investigation and remediation capabilities that help reduce the volume of alerts in minutes at scale. [Secure score](overview-secure-score-windows-defender-advanced-threat-protection.md) | Quickly assess the security posture of your organization, see machines that require attention, as well as recommendations for actions to better protect your organization - all in one place. +[Microsoft Threat Experts](microsoft-threat-experts.md) | Managed cybersecurity threat hunting service. Learn how you can get expert-driven insights and data through targeted attack notification and access to experts on demand. [Advanced hunting](overview-hunting-windows-defender-advanced-threat-protection.md) | Use a powerful search and query language to create custom queries and detection rules. [Management and APIs](management-apis.md) | Windows Defender ATP supports a wide variety of tools to help you manage and interact with the platform so that you can integrate the service into your existing workflows. -[Microsoft Threat Protection](threat-protection-integration.md) | Microsoft security products work better together. Learn about other security capabilities in the Microsoft threat protection stack. +[Microsoft Threat Protection](threat-protection-integration.md) | Microsoft security products work better together. Learn about other security capabilities in the Microsoft threat protection stack. [Portal overview](portal-overview-windows-defender-advanced-threat-protection.md) |Learn to navigate your way around Windows Defender Security Center. diff --git a/windows/security/threat-protection/windows-defender-atp/whats-new-in-windows-defender-atp.md b/windows/security/threat-protection/windows-defender-atp/whats-new-in-windows-defender-atp.md index b8352cb7d6..450fdcb9a5 100644 --- a/windows/security/threat-protection/windows-defender-atp/whats-new-in-windows-defender-atp.md +++ b/windows/security/threat-protection/windows-defender-atp/whats-new-in-windows-defender-atp.md @@ -26,6 +26,8 @@ Here are the new features in the latest release of Windows Defender ATP as well ## April 2019 The following capability is generally available (GA). +- [Microsoft Threat Experts Targeted Attack Notification capability](https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-atp/microsoft-threat-experts#targeted-attack-notification)
Microsoft Threat Experts' Targeted Attack Notification alerts are tailored to organizations to provide as much information as can be quickly delivered thus bringing attention to critical threats in their network, including the timeline, scope of breach, and the methods of intrusion. + - [Microsoft Defender ATP API](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/use-apis)
Microsoft Defender ATP exposes much of its data and actions through a set of programmatic APIs. Those APIs will enable you to automate workflows and innovate based on Windows Defender ATP capabilities. @@ -40,7 +42,7 @@ The following capabilities are included in the April 2019 preview release. ### In preview The following capability are included in the March 2019 preview release. -- [Machine health and compliance report](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/machine-reports-windows-defender-advanced-threat-protection)
The machine health and compliance report provides high-level information about the devices in your organization. +- [Machine health and compliance report](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/machine-reports-windows-defender-advanced-threat-rotection) The machine health and compliance report provides high-level information about the devices in your organization. ## February 2019