What is Advanced Threat Analytics and how does it protect your environment? (Part 1 – Installation)

Recently I’ve been doing more work around security and I decided to finally test Advanced Threat Analytics (ATA) in my  lab. ATA is a security tool that helps protect your enterprise from multiple threats. ATA focuses on several phases during a cyber-attack that includes:

  • Reconnaissance, during which attackers are gathering information on how the environment is built, what are the different assets and entities which exist and are generally building their plan for the next phases of the attack.
  • Lateral movement cycle, during which an attacker invests time and effort in spreading their attack surface inside your network.
  • Domain dominance (persistence), during which an attacker captures the information allowing them to resume their campaign using various set of entry points, credentials and techniques.

ATA consists of a lightweight gateway that is installed on each domain controller. I’ve always been a bit skeptical regarding installing anything on a DC but I’ve blew up my home lab a few times so I figured it would be ok. The ATA lightweight gateway is available via MSDN, Microsoft VLSC, and or Technet Evaluation.

Here is a look at my installation

I created an account that only has read access to connect to AD. Once the account is entered, click install to complete the setup.

In my next blog (Part 2- Using the ATA console), I will go over navigating the ATA console and reporting.

Disclaimer
All content provided on this blog is for information purposes only. Windows Management Experts, Inc makes no representation as to accuracy or completeness of any information on this site. Windows Management Experts, Inc will not be liable for any errors or omission in this information nor for the availability of this information. It is highly recommended that you consult one of our technical consultants, should you need any further assistance.

Share:

Facebook
Twitter
LinkedIn

Contact Us

Name
=
On Key

More Posts

WME Cybersecurity Briefings No. 039
Cyber Security

WME Security Briefing 09 June 2025

1. Hackers Exploit TikTok Videos to Spread Vidar and StealC Malware Via ClickFix Technique Overview Cybercriminals just recently adapted the ClickFix social engineering technique. It’s a technique that helps with  spreading malwares, Vidar and StealC, as

Read More »
WME Microsoft 365 Updates No. 017
Azure

WME Microsoft 365/Azure Updates 27 May 2025

1. Power Automate: Endpoint Filtering for Enhanced UI Automation Security Overview Microsoft Power Automate is introducing a brand new endpoint filtering feature. This feature is going to boost security in UI automation tasks. That said, the

Read More »
Azure

WME Microsoft 365/Azure Updates 13 May 2025

1. Forecast Case & Conversation Volumes with Dynamics 365 Contact Center Overview Dynamics 365 Contact Center is going to introduce a new forecasting feature this May and it’ll allow organizations to create/analyze scenarios for case/conversation volumes.

Read More »
WME Microsoft 365 Updates No. 015
Azure

WME Microsoft 365/Azure Updates 06 May 2025

1. Preview Incoming E-Invoices Before Processing in Dynamics 365 Business Central Overview A new feature is coming to Dynamics 365 Business Central which allows you to preview incoming e-invoices and credit memos before processing them. This

Read More »
Be assured of everything

Get WME Services

Stay ahead of the competition with our Professional IT offerings.

=