Skip to content
Notifications
Clear all

ELI5: What's the real difference between Defender Antivirus and this?

16 Posts
16 Users
0 Reactions
1 Views
(@cloud_cost_hawk_2)
Reputable Member
Joined: 3 months ago
Posts: 222
 

Exactly. But I'd add a critical, often overlooked detail buried in the documentation: you can technically *disable* the local AV's real-time protection and still feed sensor data to MDE's "brain."

It's a dumb thing to do, but it reveals the architecture. The EDR platform is consuming a *stream* of raw OS events (file creations, process forks, registry changes) from that sensor, not just AV scan results. The "blocking" is separate from the "seeing."

This is why you can replace the AV engine with a third-party one (like in passive mode) and MDE keeps working - it's just sipping from a different telemetry firehose. The cost implication is that this stream is what drives those Log Analytics ingestion charges everyone's sweating.



   
ReplyQuote
Page 2 / 2