Skip to content

Commit 16a920f

Browse files
committed
Learn Editor: Update attack-surface-reduction-rules-reference.md
1 parent f7fac97 commit 16a920f

File tree

1 file changed

+18
-0
lines changed

1 file changed

+18
-0
lines changed

defender-endpoint/attack-surface-reduction-rules-reference.md

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -348,6 +348,15 @@ Advanced hunting action type:
348348

349349
Dependencies: Microsoft Defender Antivirus
350350

351+
Known issues: These applications and "Block Office applications from injecting code into other processes" rule, are incompatible:
352+
353+
|Application name|For information|
354+
| -------- | -------- |
355+
||
356+
|Avecto (BeyondTrust) Privilege Guard|[September-2024 (Platform: 4.18.24090.11 | Engine 1.1.24090.11)](/defender-endpoint/microsoft-defender-antivirus-updates). |
357+
358+
Note: Please contact the third-party independent software vendor's about support.
359+
351360
### Block executable content from email client and webmail
352361

353362
This rule blocks email opened within the Microsoft Outlook application, or Outlook.com and other popular webmail providers from propagating the following file types:
@@ -482,6 +491,15 @@ Advanced hunting action type:
482491

483492
Dependencies: Microsoft Defender Antivirus
484493

494+
Known issues: These applications and "Block Office applications from injecting code into other processes" rule, are incompatible:
495+
496+
|Application name|For information|
497+
| -------- | -------- |
498+
|Avecto (BeyondTrust) Privilege Guard|[September-2024 (Platform: 4.18.24090.11 | Engine 1.1.24090.11)](/defender-endpoint/microsoft-defender-antivirus-updates). |
499+
|Heimdal security|n/a|
500+
501+
Note: Please contact the third-party independent software vendor's about support.
502+
485503
### Block Office communication application from creating child processes
486504

487505
This rule prevents Outlook from creating child processes, while still allowing legitimate Outlook functions. This rule protects against social engineering attacks and prevents exploiting code from abusing vulnerabilities in Outlook. It also protects against [Outlook rules and forms exploits](https://blogs.technet.microsoft.com/office365security/defending-against-rules-and-forms-injection/) that attackers can use when a user's credentials are compromised.

0 commit comments

Comments
 (0)