Microsoft Corporation
Anomaly lookup for cyber security hunting

Last updated:

Abstract:

Performing anomaly lookup on data sources that include an entity related to an alert. One or more entities related to an alert and a date when the alert occurred are received. The alert may indicate that an anomaly in data collected from a various data sources may be present in at least one of the data sources. The various data sources are searched for the one or more entities around the alert date to determine which of the data sources include the one or more entities. For those data sources including the one or more entities, an anomaly lookup procedure is performed on the data sources during a first time window to determine an initial set of suspicious anomalies.

Status:
Grant
Type:

Utility

Filling date:

1 Feb 2019

Issue date:

2 Aug 2022