Skip to content

Commit 18899c6

Browse files
authored
Fix typos and formatting in markdown file
1 parent 5cf6c5d commit 18899c6

File tree

1 file changed

+11
-11
lines changed

1 file changed

+11
-11
lines changed

defender-endpoint/attack-surface-reduction-rules-report.md

Lines changed: 11 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -68,7 +68,7 @@ To access the attack surface reduction rules report in the Microsoft Defender po
6868

6969
To assign these permissions:
7070

71-
1. Sign in to the [Microsoft Defender portal](https://security.microsoft.com].
71+
1. Sign in to the [Microsoft Defender portal](https://security.microsoft.com).
7272

7373
2. In the navigation pane, select **Settings** \> **Endpoints** \> **Roles** (under **Permissions**).
7474

@@ -114,7 +114,7 @@ Selecting the **ASR rules detections** link at the top of the card also opens th
114114

115115
The top section focuses on three recommended rules, which protect against common attack techniques. This card shows current-state information about the computers in your organization that have the following [Three \(ASR\) standard protection rules](#simplified-standard-protection-option) set in **Block mode**, **Audit mode**, or **off** (not configured). The **Protect devices** button shows full configuration details for only the three rules; customers can quickly take action to enable these rules.
116116

117-
The bottom section surfaces six rules based on the number of unprotected devices per rule. The "View configuration" button surfaces all configuration details for all ASR rules. The "Add exclusion" button shows the **add exclusion** page with all detected file/process names listed for Security Operation Center (SOC) to evaluate. The **Add exclusion** page is linked to Microsoft Intune.
117+
The bottom section surfaces six rules based on the number of unprotected devices per rule. The **View configuration** button surfaces all configuration details for all ASR rules. The **Add exclusions** button shows the **add exclusion** page with all detected file/process names listed for Security Operation Center (SOC) to evaluate. The **Add exclusion** page is linked to Microsoft Intune.
118118

119119
The card also includes two action buttons:
120120

@@ -258,8 +258,8 @@ To enable ASR rules:
258258

259259
:::image type="content" source="media/attack-surface-reduction-rules-report-configuration-add-to-policy.png" alt-text="Shows the ASR rules fly-out to add ASR rules to devices" lightbox="media/attack-surface-reduction-rules-report-configuration-add-to-policy.png":::
260260

261-
> [NOTE!]
262-
> If you have devices that require that different ASR rules be applied, you should configure those devices individually.
261+
> [NOTE!]
262+
> If you have devices that require that different ASR rules be applied, you should configure those devices individually.
263263
264264
### Attack surface reduction rules Add exclusions tab
265265

@@ -269,24 +269,24 @@ The **Add exclusions** tab presents a ranked list of detections by file name and
269269
- **Detections**: The total number of detected events for named file. Individual devices can trigger multiple ASR rules events.
270270
- **Devices**: The number of devices on which the detection occurred.
271271

272-
>:::image type="content" source="media/attack-surface-reduction-rules-report-exclusion-tab.png" alt-text="Shows the ASR rules report add exclusions tab" lightbox="media/attack-surface-reduction-rules-report-exclusion-tab.png":::
272+
:::image type="content" source="media/attack-surface-reduction-rules-report-exclusion-tab.png" alt-text="Shows the ASR rules report add exclusions tab." lightbox="media/attack-surface-reduction-rules-report-exclusion-tab.png":::
273273

274274
> [!IMPORTANT]
275275
> Excluding files or folders can severely reduce the protection provided by ASR rules. Excluded files are allowed to run, and no report or event is recorded.
276276
> If ASR rules are detecting files that you believe shouldn't be detected, you should [use audit mode first to test the rule](attack-surface-reduction-rules-deployment-test.md#step-1-test-attack-surface-reduction-rules-using-audit).
277277
278278
When you select a file, a **Summary & expected impact** fly out opens, presenting the following types of information:
279279

280-
- **Files selected** The number of files you've selected for exclusion
281-
- **(_number of_) detections** States the expected reduction in detections after adding the selected exclusions. The reduction in detections is represented graphically for **Actual detections** and **Detections after exclusions**
282-
- **(_number of_) affected devices** States the expected reduction in devices that report detections for the selected exclusions.
280+
- **Files selected** - The number of files you've selected for exclusion
281+
- **(_number of_) detections** - States the expected reduction in detections after adding the selected exclusions. The reduction in detections is represented graphically for **Actual detections** and **Detections after exclusions**.
282+
- **(_number of_) affected devices** - States the expected reduction in devices that report detections for the selected exclusions.
283283

284284
The Add exclusion page has two buttons for actions that can be used on any detected files (after selection). You can:
285285

286-
- **Add exclusion** which opens Microsoft Intune ASR policy page. For more information, see: [Intune](enable-attack-surface-reduction.md) in "Enable ASR rules alternate configuration methods."
287-
- **Get exclusion paths** which downloads file paths in a csv format
286+
- **Add exclusion** which opens Microsoft Intune ASR policy page. For more information, see [Intune](enable-attack-surface-reduction.md) in "Enable ASR rules alternate configuration methods."
287+
- **Get exclusion paths** which downloads file paths in a csv format.
288288

289-
:::image type="content" source="media/attack-surface-reduction-rules-report-main-add-exclusions-flyout.png" alt-text="Shows the ASR rules report add exclusions tab flyout impact summary" lightbox="media/attack-surface-reduction-rules-report-main-add-exclusions-flyout.png":::
289+
:::image type="content" source="media/attack-surface-reduction-rules-report-main-add-exclusions-flyout.png" alt-text="Shows the ASR rules report add exclusions tab flyout impact summary." lightbox="media/attack-surface-reduction-rules-report-main-add-exclusions-flyout.png":::
290290

291291
## See also
292292

0 commit comments

Comments
 (0)