Forum Moderators: open

Message Too Old, No Replies

Microsoft Defender for Endpoint Now Includes Intel Threat Detection

         

engine

11:03 am on Apr 27, 2021 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



Microsoft has announced that Windows Defender Endpoint now includes Intel Threat Detection technology to enhance the detection capability and protection against cryptojacking.malware.
This technology is based on telemetry signals coming directly from the PMU, the unit that records low-level information about performance and microarchitectural execution characteristics of instructions processed by the CPU. Coin miners make heavy use of repeated mathematical operations and this activity is recorded by the PMU, which triggers a signal when a certain usage threshold is reached. The signal is processed by a layer of machine learning which can recognize the footprint generated by the specific activity of coin mining. Since the signal comes exclusively from the utilization of the CPU, caused by execution characteristics of malware, it is unaffected by common antimalware evasion techniques such as binary obfuscation or memory-only payloads.

https://www.microsoft.com/security/blog/wp-content/uploads/2021/04/TDT-and-MD-Detect-and-Remediate-Malware.png

[microsoft.com...]