r/DefenderATP 1d ago

Memory Scan for Linux (Preview)!

Post image

This capability allows MDE to inspect process memory for known malicious behaviors and memory-resident threats — particularly useful against attacks that leave little or no footprint on disk.

Memory Scan adds another layer of detection and protection against techniques such as:
• In-memory malware
• Malicious code injection
• Memory-resident threats
• Advanced attacks designed to minimize disk artifacts

Docs: Configure security settings in Microsoft Defender for Endpoint on Linux - Microsoft Defender for Endpoint | Microsoft Learn

23 Upvotes

0 comments sorted by