Inquiry regarding the integration of Native Sysmon with Microsoft Defender on Windows 11.
amralaa-8729
695
نقاط السُمعة
"Hello Microsoft Community,
I have recently enabled the native Sysmon feature on my Windows 11 machine. I would like to know if Microsoft Defender (Antivirus/EDR) automatically leverages the detailed telemetry and events captured by Sysmon (such as Process Creation ID 1 and Network Connections ID 3) to enhance its behavioral detection capabilities.
Furthermore, does the system require any manual configuration to ensure that Defender is effectively utilizing Sysmon logs for threat hunting and protection, or is this integration handled natively by the OS?
Best regards,"
Windows for home | Windows 11 | الأمان والخصوصية
تسجيل الدخول للإجابة