Malware

Microsoft Build a New Threat & Vulnerability Management Features to Prevent Advanced Cyber Attacks

Microsoft Defender ATP is an add-on with Windows Defender Antivirus aimed to combat cyber attacks and to secure your environment. The threat & Vulnerability Management (TVM) is the latest inclusion in Microsoft Defender ATP.

At the Microsoft Ignite conference, Microsoft announced that it is working with capabilities for Threat and Vulnerability Management (TVM) to improve threat detection.

Threat and Vulnerability Management

Microsoft enhancing the capabilities of TVM to improve the time to detection and remediation, integration across platforms, and automated user-impact analysis.

Following are the new capabilities that are announced to go in public for this month

  • Vulnerability Assessment (VA) support for Windows Servers 2008 R2 and above
  • Integration with ServiceNow for improved IT/Security communication
  • Advanced hunting across vulnerabilities and security alerts
  • Role-based access controls (RBAC) for teams focusing on vulnerability management
  • Automated user-impact analysis

Microsoft aimed to extend the Vulnerability Assessment support for Windows Windows Servers 2008 R2, 2012 R2, 2016, and 2019. This enhancement helps customers to effectively discover, prioritize and remediate Windows server vulnerabilities across the entire stack, including OS components, Microsoft apps, and third-party software.

“With this new integration, the security team can open change management tickets in ServiceNow directly from the Microsoft Defender Security Center to ask the IT team to remediate vulnerabilities and misconfigurations,” reads Microsoft Blog Post.

The New addition of Role-based access controls provides system administrators flexibility to create SecOps-oriented roles, TVM-oriented roles, or hybrid roles to restrict only the authorized users can access the data.

Microsoft advanced hunting capabilities provide customers extensive flexibility in slicing and dicing vulnerability and misconfiguration data.

The last one is the ASR rules which determine which machines are considered safe for configuration change without impacting user productivity.

You can follow us on LinkedinTwitterFacebook for daily Cyber security and hacking news updates.

Guru Baran

Gurubaran is the Co-Founder and Editor-in-Chief of CyberSecurityNews.com, specializing in vulnerability analysis, malware research, ransomware, and computer forensics.

Recent Posts

China-linked APT24 Hackers New BadAudio Compromised Legitimate Public Websites to Attack Users

APT24, a sophisticated cyber espionage group linked to China's People's Republic, has launched a relentless…

1 hour ago

Broadcom Allegedly Breached by Clop Ransomware via E-Business Suite 0-Day Hack

The Cl0p ransomware group has claimed responsibility for infiltrating Broadcom's internal systems as part of…

2 hours ago

Critical Grafana Vulnerability Let Attackers Escalate Privilege

Grafana Labs has disclosed a critical security vulnerability affecting Grafana Enterprise that could allow attackers…

2 hours ago

Critical ASUSTOR Vulnerability Let Attackers Execute Malicious Code with Elevated Privileges

A critical security vulnerability has been discovered in ASUSTOR backup and synchronization software, allowing attackers…

3 hours ago

Windows 11 to Hide BSOD Crash Errors on Public Displays

Microsoft has introduced a practical new feature in Windows 11 designed specifically for public-facing monitors…

4 hours ago

SonicOS SSLVPN Vulnerability Let Attackers Crash the Firewall Remotely

SonicWall has disclosed a critical stack-based buffer overflow vulnerability in its SonicOS SSLVPN service. That…

6 hours ago