Blog Post

Microsoft Defender for Endpoint Blog
1 MIN READ

How we detect script-based attacks with Windows Defender ATP & AMSI

Jasika Bawa's avatar
Jasika Bawa
Former Employee
Dec 04, 2017

Happy Monday folks! Check out this awesome new blog post from the WDATP Research team, on unearthing script-based attacks with the combined power of WDATP and the Anti-Malware Scan Interface (AMSI):

 

https://blogs.technet.microsoft.com/mmpc/2017/12/04/windows-defender-atp-machine-learning-and-amsi-unearthing-script-based-attacks-that-live-off-the-land/

 

Process tree augmented by instrumentation for AMSI data

Updated Dec 05, 2017
Version 4.0
No CommentsBe the first to comment