I was wondering, could the MAR threat workspace and the trace rules work without any connection to the cloud? If so, please explain to me how to do this... If not, is there any alternatives to on-premise organizations?
Re: MAR Threat Workspace in on-premise envivorments
There isn't.
If you want to come closest, write Triggers against key threats and monitor any ATP containment event (at least from key parent processes) where daysbeforedetection=0.
You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.
Community Help Hub
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.