Microsoft Releases Advanced Threat Analytics Version 1.8
Microsoft released the latest version of its Advanced Threat Analytics forensic security solution this week.
Version 1.8 is a "general availability" release, meaning that Microsoft views it as ready for use in commercial environments. This release can now handle more than one million packets per second, Microsoft noted, in its announcement.
Advanced Threat Analytics is Microsoft's machine-learning forensics tool that gets installed on the customer's infrastructure. It's a "user and entity behavioral analytics" tool typically used for post-breach analyses. The tool, which tracks attack techniques and the "abnormal behavior of entities," is based on the technology Microsoft acquired when it bought Aorato.
To improve security, Microsoft added auditing logs for the Center and Gateways used with Advanced Threat Analytics. Microsoft also facilitated user access to the gateways with this release. For instance, IT pros don't have to provide credentials to access them since the gateways will "now use the logged-on user's context."
One of the new detection capabilities with version 1.8 is the ability to report "abnormal" changes in groups having elevated privileges on a network. This release also has a new detection capability for tracking "brute force" attempts to compromise user credentials. It also shows remote code execution attempts via Windows Management Instrumentation (WMI) techniques.
Version 1.8 lets organizations tell Advanced Threat Analytics when some activities are benign, and to stop pushing out alerts for certain activities. It also lets IT pros delete activities that get logged as suspicious.
Users now have access to a summary report with Advanced Threat Analytics. It shows "suspicious activities, health issues and more," which can be generated automatically, and even customized. It includes an improved "sensitive groups report" that shows "all changes" over specific time periods.
Organizations can upgrade to Advanced Threat Analytics version 1.8 (build 1.8.6645) directly from versions 1.7.1 and 1.7.2, according to Microsoft's Advanced Threat Analytics FAQ document. They have to upgrade the Advanced Threat Analytics Center first, followed by "all ATA Gateways in your environment." The software is available from the Microsoft Volume Licensing Service Center.
In other security news, Microsoft this week announced a bug bounty program for its Windows Server products. The company is paying for reports of "critical" and "important" Windows Server software flaws, with payments ranging from $500 to $250,000. Last month, Microsoft also extended its Microsoft Edge bug bounty program for reporting browser flaws.
Kurt Mackie is senior news producer for the 1105 Enterprise Computing Group.