threat protection
2 TopicsManaged Threat Experts - Targeted Attack Notification Service
Hi, I am looking into Microsoft Defender ATP and have come across the Managed Threat Experts - Targeted Attack Notification Service feature and am trying to gain a fuller understanding of the feature. I have reviewed numerous Microsoft documents and 3rd party websites and am a little confused and seeking clarification. Specifically on the points below: 1) Is there any human element to the targeted attack notification service or is the service powered purely by AI (albeit AI trained by input from real life expert threat hunters)? The marketing gives the impression there are experts from Microsoft constantly proactively reviewing your companies log information, which I am sure is not the case. 2) How is the AI and protection employed by the targeted attack notification service different from that used by the other technologies in MD ATP? Specifically, why are the threats that it detects missed by the other technologies? I'm not looking to find fault, just trying to understand what gap this feature plugs? 3) I have seen references to "alerts tailored to your organisation", but aren't all alerts tailored to your organisation anyway given they are all generated by information from your organisations users and machines? Thanks in advance for your help. Paul1.9KViews1like2CommentsWhich schema belong to which service?
Hello there, So I'm pretty familiar with KQL and MDATPs default schemas found under Advanced Hunting. There are of course some more schemas/tables found under MTP compared to MDATP (https://security.microsoft.com/advanced-hunting Is there any general cheat-sheet on which schema originates from which service? For example if I would hunt under the "MiscEvents" schema, what do I need to do to add it? What I mean is, I would like to try this query: https://techcommunity.microsoft.com/t5/microsoft-defender-atp/hunting-for-reconnaissance-activities-using-ldap-search-filters/ba-p/824726 But I can't seem to find "MiscEvents" in either Log Analytics, Defender ATP or M365 Threat Protection. Do I miss something? Is Azure ATP needed for the "MiscEvents" table to be populated? Regards SimonSolved2.1KViews0likes2Comments