Skip to content

Commit ce0748b

Browse files
authored
Merge pull request #2112 from YongRhee-MSFT/docs-editor/hardware-acceleration-and-mdav-1733438636
Update hardware-acceleration-and-mdav.md
2 parents e4044c4 + 0a82bbb commit ce0748b

File tree

1 file changed

+10
-7
lines changed

1 file changed

+10
-7
lines changed

defender-endpoint/hardware-acceleration-and-mdav.md

Lines changed: 10 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -7,13 +7,16 @@ manager: deniseb
77
ms.reviewer: yongrhee
88
ms.service: defender-endpoint
99
ms.topic: overview
10-
ms.date: 09/18/2024
10+
ms.date: 12/05/2024
1111
ms.subservice: ngp
12+
ms.collection:
13+
- m365-security
14+
- tier2
15+
audience: ITPro
1216
ms.localizationpriority: medium
1317
ms.custom: partner-contribution
1418
search.appverid: MET150
1519
f1 keywords: NOCSH
16-
audience: ITPro
1720
---
1821

1922
# Hardware acceleration and Microsoft Defender Antivirus
@@ -40,16 +43,16 @@ This table shows the Intel TDT technologies Microsoft collaborated with Intel on
4043

4144
|Available since |Intel TDT technology | Intel Threat Detection Technology (TDT) available on|
4245
|:---|:---|:---|
43-
|2018|Intel TDT – Accelerated Memory Scanning (AMS)|Intel integrated graphic 6th Gen Core (circa 2015) or newer family of processors, running on laptops, tablets, and desktop systems.|
44-
|2021|Intel TDT - Cryptojacking detector| Intel 6th Gen Core (circa 2015) or newer family of processors, running on laptops, tablets, and desktop systems.|
45-
|2022|Intel TDT - Ransomware detector| Intel 8th Gen Core or newer family of processors.|
46+
|2018|Intel TDT – Accelerated Memory Scanning (AMS)|Intel integrated graphic sixth Gen Core (circa 2015) or newer family of processors, running on laptops, tablets, and desktop systems.|
47+
|2021|Intel TDT - Cryptojacking detector| Intel sixth Gen Core (circa 2015) or newer family of processors, running on laptops, tablets, and desktop systems.|
48+
|2022|Intel TDT - Ransomware detector| Intel eighth Gen Core or newer family of processors.|
4649

4750
**Intel Threat Detection Technology (TDT) - Accelerated Memory Scanning (AMS):** Introduced extra memory scanning capabilities to detect fileless attacks that are expensive on the Central Processing Unit (CPU), and then offload them to the integrated Graphics Processor Unit (integrated GPU). Two benefits are:
4851

4952
- lower CPU consumption
5053
- A reduction of System-on-a-chip (SoC) power consumption leading to longer battery life on laptops and tablets
5154

52-
**Intel Threat Detection Technology (TDT) - Cryptojacking:** Enhanced detection by leveraging Intel's Central Processing Unit (CPU) performance monitoring unit (PMU) and offloading to the integrated Graphics Processor Unit (integrated GPU) to detect the malware code execution (fingerprint) of repeated mathematical operations at runtime. The signals are processed by a layer of machine learning with minimal overhead.
55+
**Intel Threat Detection Technology (TDT) - Cryptojacking:** Enhanced detection by using Intel's Central Processing Unit (CPU) performance monitoring unit (PMU) and offloading to the integrated Graphics Processor Unit (integrated GPU) to detect the malware code execution (fingerprint) of repeated mathematical operations at runtime. Machine learning processes signals with minimal overhead.
5356

5457
### How do you enable Intel TDT AMS or Cryptojacking integration?
5558

@@ -61,7 +64,7 @@ The regular Microsoft Defender Antivirus Event ID **1116**.
6164

6265
### What type of attacks does it help with?
6366

64-
- We use the Intel TDT - Cryptojacking detector to thwart various cryptojacking mallards. The following Coinminer campaigns were successfully detected and blocked using the TDT Cryptojacking detector: [YouTube Pirated Software Videos Deliver Triple Threat: Vidar Stealer, LaPlasa Clipper, XMRig Miner](https://www.fortinet.com/blog/threat-research/youtube-pirated-software-videos-deliver-triple-threat-vidar-stealer-laplas-clipper-xmrig-miner)
67+
- We use the Intel TDT - Cryptojacking detector to thwart various cryptojacking malware. The following Coinminer campaigns were successfully detected and blocked using the TDT Cryptojacking detector: [YouTube Pirated Software Videos Deliver Triple Threat: Vidar Stealer, LaPlasa Clipper, XMRig Miner](https://www.fortinet.com/blog/threat-research/youtube-pirated-software-videos-deliver-triple-threat-vidar-stealer-laplas-clipper-xmrig-miner)
6568

6669
- We use the Intel TDT detector to identify instances of CryptoJacking malware abusing Windows binaries (lolbins), and then employ Defender behavior monitoring to prevent and block such activities effectively. For more information, see [Hardware-based threat defense against increasingly complex cryptojackers](https://www.microsoft.com/security/blog/2022/08/18/hardware-based-threat-defense-against-increasingly-complex-cryptojackers/).
6770

0 commit comments

Comments
 (0)