Add component to select MS Defender install
A VM deploy should be able to add endpoint protection features. MS Defender is one such option.
Instructions for Ansible deployment are here: https://learn.microsoft.com/en-us/defender-endpoint/linux-install-with-ansible
According to the data security team, all services exposed to the internet need to install:
- A vulnerability management solution - Nessus Vulnerability Scanner.
- An Endpoint Detection and Response tool. - Microsoft Defender for endpoint protection.
In this issue, we are going to see how we can install MS Defender for endpoint protection.
MS Defender is an Endpoint Detection and Response tool. The security controls it provides are essentially alerting and blocking malicious malware/processes/etc. It’s actively scanning the processes and actions a user takes (suspicious script alerts, dangerous registry changes, file/log deletion, etc.) to alert our SOC on a potentially compromised machine. It is not a vulnerability scanner, and it provides mitigating controls AFTER a machine is compromised or during the initial compromise. It also gives the SOC the ability to quarantine a compromised machine, to prevent it from infecting other machines on the network.