0
(0)

Suspicious Activity Monitoring is a feature included in Malwarebytes Endpoint Detection and Response. It watches for potentially malicious behavior by monitoring the processes, registry, file system, and network activity on the endpoint. Suspicious Activity Monitoring uses machine learning models and cloud-based analysis to detect when questionable activity occurs.

Detections are highlighted for your review in the menu pane under Suspicious Activity. Not all activity detected is guaranteed to be malicious, some detections are triggered by benign operations on the system.

The Suspicious Activity screen gives context for each detection to help determine whether the activity is truly malicious. Once an administrator understands what triggered the detection, they can choose to remediate the threat or close the incident as an expected behavior.

Feature requirements

  • Subscription to Malwarebytes Endpoint Detection and Response.
  • For optimal performance, reserve 1.1Mbps of network bandwidth for every 100 endpoints that use Suspicious Activity Monitoring.

To enable Suspicious Activity Monitoring and manage related events, see:

Return to the Malwarebytes Nebula platform Administrator Guide.

  • Haga clic AQUÍ para ver el manual en español.
  • Clique AQUI para o manual em Portugues.

Source : Official Malwarebytes Brand
Editor by : BEST Antivirus KBS Team

How useful was this post?

Click on a star to rate it!

Average rating 0 / 5. Vote count: 0

No votes so far! Be the first to rate this post.

(Visited 5 times, 1 visits today)