Windows Defender getting an overhaul in RS2

Mar 14, 2017 12:14 GMT  ·  By

Windows 10 Creators Update (internally known as Redstone 2) will come with a long list of improvements, including new security features for Windows Defender, which itself is getting a major overhaul.

Today, Microsoft is highlighting some of the features to be available in Windows Defender ATP, explaining that securing a Windows 10 PC comes down to three major stages: detection, investigation, and response.

Windows 10 Creators Update integrates new features that are typically available in third-party antivirus software, such as better detection of memory and kernel-level attacks, which already proved very effective at blocking zero-day exploits targeting unpatched OS vulnerabilities. Ransomware is also receiving particular attention from the firm, and so do other advanced attacks, Microsoft guarantees.

Continued anti-ransomware efforts

The software giant explains that Windows Defender ATP has been improved to provide an inside into actions, relationships, and alerts to keep an eye on security and manage detections as they occur.

“Our alert page now includes a new process tree visualization that aggregates multiple detections and related events into a single view that helps security teams reduce the time to resolve cases by providing the information required to understand and resolve incidents without leaving the alert page,” the firm says.

When it comes to investigation, Windows Defender antivirus and Device Guard are the first two layers of security supposed to assist users in this stage.

As far as the response is offered, Microsoft makes it easier for security administrators to act fast, with options to isolate machines, ban files from the network, and kill processes that are infected.

All these features will be available in the Windows 10 Creators Update launching next month and there’s now word that the RTM build should be ready these days before being shipped to insiders the next week.