ummm....simply put viruses, spyware, and other malicious software
And now the jargon....
MSE real time protection mechanism operates at the kernel level to examine the behavior of unknown binaries and then sandbox potential malware before it can do any harm.It has heuristic detection capabilities too. And due to a new Dynamic Signature Service, MSE can immediately query online to see if there is anything that matches what its seeing on the PC. Because of its kernel mode hooks, MSE can also detect kernel mode rootkits and, in many cases, even clean them out after they've rooted their way into the system.
as with any other av/as it can be bypassed by new/zero day threats..especially rouge av/as cause they are a pita
ideally use it in conjunction with something like mbam pro