Hi Hany
The ATA Gateway service (doesn’t matter if it is the ATA Gateway or the Lightweight Gateway), will resolve the IP addresses seen in the network traffic to a computer name. This active network name resolution
is performed by attempting to contact the IP address either with NTLM over RPC or NetBIOS connection. This gives ATA the highest confidence of the name of the device that is sending that traffic. Just looking at the IP address is not sufficient as IP
addresses assigned to a device will change, even multiple times a day. ATA will then lookup to see if there is an object in AD with the same name.
This requirement is documented in the requirements for the Lightweight Gateway located here,
https://docs.microsoft.com/en-us/advanced-threat-analytics/plan-design/ata-prerequisites#ata-lightweight-gateway-requirements.
HTH
ATA Customer Experience Team
Gershon Levitz [MSFT]