Skip to content
  • Home
  • Emerging Technology & News
  • Computer Help
  • Privacy and Security
  • Reimage Windows Repair
The Reimage Blog
Menu
  • Home
  • Emerging Technology & News
  • Computer Help
  • Privacy and Security
  • Reimage Windows Repair
Facebook Twitter
Home  /  Privacy and Security  /  Microsoft’s new security tool lets you see your systems like a hacker would
PostedinPrivacy and Security Posted on August 8, 2022

Microsoft’s new security tool lets you see your systems like a hacker would

Posted By Matthew.England

Microsoft has launched two security services that aim to boost the intelligence capabilities of an organization’s security operations center (SOC) rather than solely protect devices. 

Microsoft has launched Defender Threat Intelligence and Defender External Attack Surface Management (EASM) — two new products that merge technology Microsoft gained after acquiring security firm RiskIQ last July for $500 million.

There may appear to be some overlap between Microsoft’s existing services, such as its Azure-powered Sentinel security information and event management (SIEM) service and Microsoft Defender Experts for Hunting, a managed threat hunting service, and its Defender Experts for XDR, a managed extended detection and response (XDR) service.

But Microsoft says these RiskIQ-based threat intel service offerings differ in that they provide customers with “direct access to real-time data” from Microsoft’s security signals. Microsoft chief Satya Nadella last week said the firm receives 43 trillion security signals each day. 

Besides signals, Microsoft says its new threat intel service is based on intel merged between RiskIQ, Microsoft’s nation-state tracking team, Microsoft Threat Intelligence Center (MSTIC, pronounced ‘Mystic’), and the Microsoft 365 Defender security research team.

Rob Lefferts, corporate VP of Microsoft Modern Protection and SOC unit, tells ZDNet the threat intel service is about “connecting SOCs with Microsoft’s own researchers from MSTIC”.

Meanwhile, Microsoft Defender External Attack Surface Management is about “how do we make sure that you get to see the whole world the way that the attacker would,” says Lefferts.

“We’re gonna scan the internet and help you understand what do you present out on the public internet and what exposure does that mean for your company.”

The attack surface management service could be useful given that attackers start scanning the internet for exposed vulnerable devices within 15 minutes of a major flaw’s public disclosure and generally continue scanning the internet for older flaws, such as last year’s nasty Exchange Server flaws, ProxyLogon and ProxyShell. 

This service discovers a customer’s unknown and unmanaged resources that are visible and accessible from the internet – giving defenders the same view an attacker has when they select a target. Defender EASM helps customers discover unmanaged resources that could be potential entry points for an attacker. 

Across MSTIC and Microsoft 365 Defender Research, Microsoft is tracking 250 different actors and ransomware families.

“We’re providing intelligence across all of them and bringing that into your security team — not just to learn the latest news… but also to explore it, so if I see an indicator, I might explore where that might live on the network and connect that to what I’m seeing in my company. It’s like a workbench for analysts inside a company,” says Lefferts.

Microsoft’s security business is growing at a rapid clip. It was worth $10 billion a year in 2021, and as of April had grown to become a $15 billion a year business. At its Q4 FY 2022 earnings update, Nadella said Microsoft’s “security revenue increased 40 percent” and that its security business now spans 50 categories, well beyond its Defender antivirus for Windows PCs.

Other recent acquisitions include IoT security firms CyberX and ReFirm Labs to boost its cybersecurity offerings.

Microsoft rebranded its Defender lineup in 2020 to bring Microsoft Threat Protection, Defender ATP, Azure Security Center, and others brought under the Microsoft Defender monicker. Microsoft Defender would become its XDR product, while Azure Sentinel became its SIEM line.

Lefferts says the two new Defender-branded services are standalone products. 

“This is different to protecting endpoints. It’s about improving your security team, giving them new views and perspectives. If you think about a game of chess, if you turn it around and look at it from your opponent’s point of view, this is a tool that is designed to help analysts do that by giving them that different perspective,” he says.

Source: https://www.zdnet.com/article/microsofts-still-unannounced-designer-tool-new-details-emerge/
Image: The Good Brigade / Getty

Share on Facebook Share on Twitter
Previous Article
Ultrasound stickers could continuously image internal organs for days
Next Article
Your Macs Aren’t as Secure as You Think

About Author

Matthew.England

Related Posts

  • Ransomware access broker steals accounts via Microsoft Teams phishing

    September 13, 2023
  • Abnormal Security: Microsoft Tops List of Most-Impersonated Brands in Phishing Exploits

    September 7, 2023
  • FBI: Hackers Are Having a Field Day With Open-Source AI Programs

    August 10, 2023
Scan Now

Categories

  • Business
  • Computer Help
  • Emerging Technology & News
  • Privacy and Security
  • Reviews

Reviews

Reimage Social

Security

Popular Posts

  • PCWorld calls Reimage “A Fantastic Repair Utility “ July 26, 2011 Reviews
  • 4 Ways to Keep the Ghouls & Goblins Away From Your PC October 26, 2010 Archive
  • The PC Key to Happiness - A Properly Maintained OS September 2, 2010 Archive
  • Google says hacked websites were attacking iPhones for years September 12, 2019 Privacy and Security

Random Posts

  • Samsung will spend $205 billion in strategic plan to conquer semiconductors, robotics, and more August 25, 2021 Business
  • Foxconn says the AI server market will increase fourfold in four years August 17, 2023 Business
  • Tech giants Amazon, Apple, and Samsung could be major investors in Arm’s IPO August 15, 2023 Business
  • FBI: Hackers Are Having a Field Day With Open-Source AI Programs August 10, 2023 Privacy and Security
© Copyright 2019
We use cookies to ensure that we give you the best experience on our website.Ok