Patent attributes
This disclosure describes threat detection monitoring of systems executing in environments (consisting of hosts, networks, and/or applications, etc.), e.g., service provider networks, using trained deep learning/machine learning (ML) models. The models may be trained in one or more stages in simulators within a service provider network, e.g., the cloud, and/or in a simulator located in an on-premises environment, as well as on systems executing within the network. The models may be trained without relying on any security device/feature being configured or enabled, or with such security device/features being configured or enabled.