Your organization may subscribe to threat feeds (including Symantec DeepSight) that provide information about current threats to your environment. These services provide indicators of compromise (IOC)s that let you know what artifacts to search for in your environment. You may also learn about malware activity through sandboxing results or you may have become aware of a trending malicious threat through a news source.
ATP lets you search its database and Symantec Endpoint Protection endpoints for IOCs.
Click the following link to learn more about how the searches differ, when to use each type of search, and what is supported.