104k views
3 votes
What information sources does Azure ATP use?

User Elzapp
by
8.3k points

1 Answer

3 votes

Final answer:

Azure ATP uses network traffic data, domain controller logs, and user behavior analytics as information sources to detect threats.

Step-by-step explanation:

Azure ATP uses a variety of information sources to analyze and detect threats in an organization's network. These sources include:

  • Network traffic data: Azure ATP collects and analyzes network traffic data, looking for suspicious patterns and behavior.
  • Domain controller logs: Azure ATP integrates with Active Directory domain controllers to analyze security events and detect anomalies.
  • User and entity behavior analytics: Azure ATP uses machine learning algorithms to analyze the behavior of users and entities, identifying any deviations from normal patterns that may indicate a potential threat.

By leveraging these information sources, Azure ATP provides organizations with valuable insights into the security of their networks, helping to identify and mitigate potential threats.

User TotalNewbie
by
8.4k points

No related questions found