Microsoft Defender ATP for Linux is now generally available
techcommunity.microsoft.com
techcommunity.microsoft.com
Also I'm guessing it's easier for admins of mixed infra to have a single threat definition (ie. So your storage server catches the same threats as your endpoints)
5.1 Deploy anti-virus software on all systems commonly affected by malicious software (particularly personal computers and servers).
It's typically an ignorant CISO/CSO who wants to mark a checkbox...
Easier just to say "AV on everything".
At the same time, ClamAV has a terrifying CVE track record.
There's no upside, and all downside.
ClamAV: https://www.cvedetails.com/product/15657/Clamav-Clamav.html?...
Norton AV: https://www.cvedetails.com/product/398/Symantec-Norton-Antiv...
Windows Defender: https://www.cvedetails.com/product/9767/Microsoft-Windows-De...
It may be safer to say that the CVE record for most AV software isn't great.
Given that, a possible upside with ClamAV could be that you could verify the behaviour of the processes on the installed systems, to make sure you're up-to-date and have the correct software and signatures installed.
That's not unreasonable - Microsoft's software delivery pipeline should be trustworthy and their security reputation could be damaged if an issue were discovered here.
That’s true of everything installed on a system - if you don’t control the software you’re running, Defender is the least of your worries. Unless you’re doing a full analysis of every binary you’re trusting the source.
We’re in the middle of adopting HiTrust and I’ve been forced to install Cisco AMP on all of my servers. The product is absolute garbage and frequently eats up all available RAM, causing itself to crash and leave a core dump filling up my root partition.
The worst part? AMP on Linux is literally ClamAV plus a kernel module to monitor file access, network connections and process creation.
People don't give Microsoft money for a product that's not by Microsoft. If Microsoft offers one, and can even claim that they cover all platforms with one overarching offering, companies pay them for it.
You may not want a product like this on Linux. But if you do business in the DoD supply chain, even way down the chain, then you will be required to do so.
If you’re not vulnerable and don’t need the badge you can’t be taken seriously.
It’s all very amusing!
Though I have a hunch this won't be free software and will have all kinds of telemetry you can't disable.
The Linux ecoystem has consistently p it their fingers in their ears and stop informing the very real and long outstanding problems of malware and apts
Those are the options. Head completely in sand or get some sand in your eyes
A good linux example would be httpd starting netcat that connects to a remote port. Or firefox spawning a bash shell. For windows a simple example would be when an office app starts wscript or powershell and that child process schedules taks, wmi, downloads a payload,etc... Those are simple examples but they track more complex attack scenarios, for cloud hosted solutions like defender atp and crowdstrike they also collect everything that happens on every device of every customer, so if they find new malware or an attacker with a certain TTP on one device, they will deploy rules to catch that for all their customers.
Security mandates such as PCI mandate running anti-virus and friends on a per host basis. They demand a 24-hour event review, FIM, etc. If tools like this come to Linux, it'll make it significantly easier for many organizations to start complying with these mandates. To be clear - these organizations already take security at best as a suggestion - these tools help reduce the barrier to entry so that at least the basics can be addressed.
I'd imagine that well over 95% of Linux users would never run Microsoft tools on Linux. At the same time, for those Windows shops that are experimenting with Linux, or need to support a few workloads, can't afford the dedicated expertise (yet) this is definitely a step forward to help them.
You said a lot more than you probably intended. Microsoft created the Microsoft-loving, Linux-hating trade press in the 90's. Consultancies fell into line, and started pushing the theory to uncritical IT management that if you had a computer connected to the corporate network, it had to run a virus scanner. Period; full stop. Regardless of operating system.
I've never met anyone in corporate IT who actually does the math, and determines whether a particular threat vector is worth the cost of the preventative measure. The philosophy in the 3 Fortune 250's I've worked for has been: if it exists, it must be purchased/used/applied. In the 90's, yes, every WINDOWS computer connected to the corporate network needed the corporate AV running on it. Linux? Mac? Not so much. Even if they managed to get compromised, the chance that they would infect a neighboring computer were very small. These odds didn't justify the expense or the hassle of needing them to slaved into the corporate AV solution, no matter how much Microsoft diverted attention away from the very special problem that Windows has always posed from a security standpoint, how much they paid the trade press to paper over it, and how much they partnered with consultancies to push that line. They didn't care about the mainframe, did they? They didn't care about the Unix workstations, either. But Linux? It was the devil.
We have come full circle. Microsoft is trying their hardest to astroturf the message that WSL enables a lot of development workflows for which Windows has been a poor choice of late, and this requires them to "love Linux." So now Microsoft MUST release their Defender product for Linux, in order to be taken seriously BY THE VERY CULTURE THEY CREATED. As a guy who run Linux on the desktop for 19 years, and got my corporate IT (in the 90's) to consider Linux all the way to the point of them looking into a virus scanner for it (finding that Symantec didn't support it, and dropping the idea), the irony here is both delicious and sickening at the same time.
As I keep saying, I'll believe Microsoft "loves" Linux they day they create Office and an AD client for it.
Adobe too. Man would it be fantastic to see Adobe add support. Same thought pops in my head: they're already running on UNIX, how much would be required to port to Linux? Probably more than I expect.
99% of the (few) Windows programs I still routinely use work perfectly fine under Wine. I can even run my old Windows 3.1 (16 bit) stuff on 64 bit Ubuntu, which I couldn't run on Windows 10. Heck when I was a Linux newbie, I was amazed to find Windows programs that didn't support Windows XP links were nicely following Ext symlinks!
Office doesn't play nice on Wine? Seriously, if Valve can get stuff working on Proton that requires DRM, DirectX etc. it doesn't look like fixing existing issues to make Office work 100% under Wine is beyond reach for Microsoft. Heck, we're talking about the same corporation capable of giving us the WSL!
> Adobe too.
And Autodesk too.
Indeed. I was happily using Codeweaver's Crossover product to run Office 2000 (on RedHat 6.2 with Ximian Desktop, IIC) before Microsoft realized this loophole produced a flawless experience, and then changed the binaries to purposely frustrate this solution going forward. Nothing every worked quite right after that. Eventually, Evolution had a usable Exchange integration, and OpenOffice wasn't completely useless, so I simply stopped caring.
Exactly. Everything else is just a marketing gimmick. They don't even support interoperability between OOXML, thus crippling every other "enterprisey" user who might want to have usable content/data between their co-workers who might be using Windows
MS-Uservoice has ~500 comments on this topic since 2018, and no word from MS till now. [ https://office365.uservoice.com/forums/264636-general/sugges... ]
Guess they figured out WSL is an easy ticket to
- paint the picture that "MS <3 linux! Techbros, dont'cha see! Yeah!" - thus counter the "Hard for Ubuntu/Fedora/Linux users to use MS Apps!" argument by going "Know what, Ubuntu is within Windoze! No need to dual boot now! Wow! Such advancement!" and find a way to safeguard and maximize license/OS-aaS revenue
- no need to ever invest in interoperability for OOXML and such defined standards (this is a great lesson they have learnt from the LDAP-MSAD story)
- no need to bother much the "situation" of dual-boot - now there's a better way, by saying, "you could run Linux within, with full native suppirt, and no need to go out-of-band from your corporate security and compliance baselines! So much win, ya'see!"
Look beyond the gimmicks, and one could see it's just the same objective - just a different approach now.
Not just "Windows on every desktop" but rather, "all data-processings units in the world to directly be leading in one way or other to cause some kida revenue flow for MS"
Regarding AD clients, what are you looking for that's not well covered by LDAP clients and all the AAD connection capabilities built into Azure? AKS runs RBAC based on bindings to AAD. Certainly for any server workloads, AD integrations are well covered.
Perhaps the clarification Yu out need is, microsoft loves Linux on the server. They don't particularly care about linux on the desktop.
Microsoft is a company, suggesting a company "Loves" anything is a misnomer. I say this because I sort of disagree here, but only kind-of.
Microsoft embraces ("Loves") the parts of Linux which are compatible with Microsoft's strategy. Linux on Azure is getting quite huge, it's the difference between Azure existing as a profitable business for Microsoft and Azure being a cost center. Microsoft does a fair amount to embrace Linux on the server, they support Docker, they do a lot of work with Node, and have a fair number of people onboard doing Linux specific stuff.
Linux AD & Office are only really important to desktop deployments and Microsoft has zero strategic interest in the Linux Desktop. If Microsoft were to port Office & AD to Linux Desktop, it would be an act of charity. If Microsoft is doing charity work, there are a lot of projects I'd like to see them invest in before AD and Office on Linux.
For Microsoft? Windows has been on decline in importance at Microsoft for some time.
For Windows? Nah, too many Fortune 500 businesses rely on software running on Windows for day to day operations. While it's hard to see from the consumer/ web/ developer side of the world, Win32 still dominates. Lots of vertical industry specific software which won't be replaced for quite some time.
It's also worth noting that they encouraged startups to offer ATP support and then within a couple of years killed them by offering their own.
5.1 Deploy anti-virus software on all systems commonly affected* by malicious software (particularly personal computers and servers).
Since the majority of *nix servers aren't commonly affected, there's no reason/requirement to deploy A/V. Now this doesn't mean your boss won't require it, "just to be sure."
as someone in the security industry, my experience is that Linux servers are clearly more frequently affected than osx, and there are very few people left who would say osx doesn't have malware still.
just because a large compiled library of code doesn't exist and isn't commonly passed around doesn't mean it's malware free or even malware light.
compiled sttaic malware isn't common because it doesn't have to. rce is done on Linux systems an overwhelming majority of the time using native applications in the way they are meant to be used, just by the wrong people. (the attacker). the lack of quality security tool for the Linux environment is THE biggest concern mature security teams struggle with.
Linux is the most common internet facing os platform, and I'm here to tell you, if it's internet facing, it have threat actors targeting AND affecting it. the only reason Linux hasn't surpassed windows in how frequently is it the victim of malware/attacks is because of workstations.
And if you're managing your servers properly, A/V is unnecessary; first there are few viruses and malware that affect *nix, second, if you can't control code deployment on your systems, you're in the wrong business.
None of our systems providing Internet services are directly connected; everything is proxied/firewalled etc.
If you're expecting ANY of the A/V solutions out there to protect your systems, whether they're Windows/Linux/MacOS, you're going to be sadly disappointed when you get rooted.
I would not install this since it talks to Microsoft servers. I don't want "telemetry" sent to them.
It randomly picks files to send to MS for analysis and hijacks 50%+ of the CPU to do it.
I legitimately don’t understand what it’s trying to accomplish other than another being a telemetry vacuum for MS.
We use https://www.crowdstrike.com/ and never had any issues so far. Very low CPU usage, no false positives. Not sure if it actually does anything ;).
EDIT: But to be honest, Antivirus is just Old-school protection, it never detected anything outside 'already known viruses', Snort/Suricata on the other hand detected quite often that something is going on.
EDIT2: With "quite impressed" i mean, the performance was not much worse
>It's not different in that sense - you still need to define what to look for.
Absolutely correct, i said nothing else, just that i found much more this way than with a locally installed Antivirus, there is just one measurement for a real secure connected computer..that is cable out ;)
This is irritating but as mentioned a not unusual side effect. A good thing is they have sample submission that was fast and efficient.
Wait...you think that is something good, they criticized Kaspersky exactly for that.
Why do you think it's not?
Those that want to contribute their samples in order to have them white/blacklisted can, but just because a feature is there doesn't mean somebody is forcing you to do it, nor that it's inherently bad because you're willingly uploading files to a 3rd party.
How, exactly, would you expect AV/security companies to be able to analyze samples that are actually relevant to their customers if they're not submitted? They would never be able to find nearly as much malware on their own.
It can analyze an attackers moves within your network, figuring out what files they accessed, ways they pivoted, and other stuff. So not only would it detect that you got compromised, but the display will show you likely paths, names of users that are also compromised, mitigation steps, deployed persistence measures, etc.
So for Defender ATP to work optimally in a deployment that leverages linux nodes, or has users using linux as their daily driver, you need to support linux.
Defender, in its current state, rolls all of the above into one at a relatively competitive price point. Additionally, it receives new detections built off all the telemetry they get as a result of Windows Defender existing on almost every Win10 OS on the planet.
This leveraging of data on such a scale is letting Microsoft quickly become the market leader for threat detection & response.
What's it sending? Fucked if I know. I figured they couldn't help themselves, though.
Or better yet: a Windows-like or Windows-compatible desktop that can run on any number of systems (and maybe corporate support is available for Debian, CentOS)? Let's not forget that the co-founder of Gnome has been working for Microsoft since 2016.
The comparison of relevance is Github. Microsoft was using Github so much already that the prospect of someone else buying them was an issue (not to mention the joke that buying Github was cheaper than paying for Microsoft's growing use of the platform). In practice, has Microsoft done anything to Github that has limited them in any way? The biggest change is that Github has a super-rich benefactor and they can offer free accounts to everyone now... and their budget for hiring/retaining top talent has been boosted as well.
Microsoft has more than enough money to do the same with Canonical and if they do I think it will largely be a matter of making sure Canonical doesn't need to worry about finances anymore and can hire whomever they need to build and deliver features. And yes, it's possible that Azure Linux applications might be available on Ubuntu first but extending and extinguishing Ubuntu would be massively opposed to making money on Azure -- I don't see Microsoft doing that.
What about just the last letter: Windows X
Of course Windows 10 is the last major version of Windows, so you got to have that in the name: Windows 10X
I guess it's similar to the way many vendors have a "EDR" version of the malware protection as opposed to the consumer version, which often reserve Linux protection for the former.
https://en.wikipedia.org/wiki/Security_through_obscurity
Edit: Link
EDIT: For the down-voter that was ironic, try copy lots of files from one Disk to another (in Windows) and during the copy-progress disable Defender...huge "performance" gain