Endpoint Detection and Response (EDR): Defender for Endpoint continuously records endpoint behaviors and analyzes them to detect, investigate, and respond to advanced threats, providing visibility into attacker activity that signature-based protection alone would miss.
02
Next-generation antivirus / antimalware protection: The platform delivers cloud-powered, behavior- and machine-learning-based antimalware protection that blocks viruses, ransomware, and other malicious software in real time.
03
Attack surface reduction rules: Configurable rules block common attack techniques and risky behaviors (such as certain Office macro and script behaviors), proactively shrinking the avenues attackers can use to gain a foothold.
04
Threat and vulnerability management: Built-in vulnerability management discovers software vulnerabilities and misconfigurations on endpoints and prioritizes them by risk, linking weaknesses directly to the devices that carry them.
05
Automated investigation and remediation: The platform can automatically investigate alerts, determine whether they represent real threats, and remediate them (such as removing malicious files or stopping processes), reducing the manual workload on analysts.
Your plan caps how many capabilities are shown — upgrade to see the full list