Skip to content

Commit 174de53

Browse files
Merge pull request #3463 from YongRhee-MSFT/docs-editor/whats-new-in-microsoft-defende-1744409405
Update whats-new-in-microsoft-defender-endpoint.md
2 parents c67989e + b6b9d2c commit 174de53

File tree

1 file changed

+7
-0
lines changed

1 file changed

+7
-0
lines changed

defender-endpoint/whats-new-in-microsoft-defender-endpoint.md

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -50,6 +50,13 @@ For more information on what's new with other Microsoft Defender security produc
5050

5151
- (Preview) **Contain IP addresses of undiscovered devices**: Containing IP addresses associated with devices that are undiscovered or are not onboarded to Defender for Endpoint is now in preview. Containing an IP address prevents attackers from spreading attacks to other non-compromised devices. See [Contain IP addresses of undiscovered devices](respond-machine-alerts.md#contain-ip-addresses-of-undiscovered-devices) for more information.
5252

53+
- (GA) **Attack Surface Reduction (ASR) Rules**
54+
55+
Two new ASR rules are now generally available:
56+
57+
- [Block rebooting machine in Safe Mode](/defender-endpoint/attack-surface-reduction-rules-reference): This rule prevents the execution of commands to restart machines in Safe Mode.
58+
- [Block use of copied or impersonated system tools](/defender-endpoint/attack-surface-reduction-rules-reference): This rule blocks the use of executable files that are identified as copies of Windows system tools. These files are either duplicates or impostors of the original system tools.
59+
5360
## February 2025
5461

5562
- (GA) **Aggregated reporting in Microsoft Defender for Endpoint** is now generally available. For more information, see [Aggregated reporting in Microsoft Defender for Endpoint](aggregated-reporting.md).

0 commit comments

Comments
 (0)