Skip to content

Commit 3e44198

Browse files
committed
Update attack-surface-reduction-rules-reference.md
1 parent 6850efc commit 3e44198

File tree

1 file changed

+5
-5
lines changed

1 file changed

+5
-5
lines changed

defender-endpoint/attack-surface-reduction-rules-reference.md

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -93,7 +93,7 @@ The following ASR rules DO NOT honor Microsoft Defender Antivirus exclusions:
9393
| [Block Office communication application from creating child processes](#block-office-communication-application-from-creating-child-processes) |
9494

9595
> [!NOTE]
96-
> For information about configuring per-rule exclusions, see the section titled **Configure ASR rules per-rule exclusions** in the topic [Test attack surface reduction rules](attack-surface-reduction-rules-deployment-test.md).
96+
> For information about configuring per-rule exclusions, see the section titled **Configure ASR rules per-rule exclusions** in the article [Test attack surface reduction rules](attack-surface-reduction-rules-deployment-test.md).
9797
9898
## ASR rules and Defender for Endpoint Indicators of Compromise (IOC)
9999

@@ -179,10 +179,10 @@ Toast notifications are generated for all rules in Block mode. Rules in any othe
179179

180180
For rules with the "Rule State" specified:
181181

182-
- ASR rules with `\ASR Rule, Rule State\` combinations are used to surface alerts (toast notifications) on Microsoft Defender for Endpoint only for devices at cloud block level "High"
183-
- Devices that not at the high cloud block level don't generate alerts for any `ASR Rule, Rule State` combinations
184-
- EDR alerts are generated for ASR rules in the specified states, for devices at cloud block level "High+"
185-
- Toast notifications occur in block mode only and for devices at cloud block level "High"
182+
- ASR rules with `\ASR Rule, Rule State\` combinations are used to surface alerts (toast notifications) on Microsoft Defender for Endpoint only for devices set at the cloud block level `High`.
183+
- Devices that are not set at the cloud block level `High` don't generate alerts for any `ASR Rule, Rule State` combinations.
184+
- EDR alerts are generated for ASR rules in the specified states, for devices set at the cloud block level `High+`.
185+
- Toast notifications occur in block mode only and for devices set at the cloud block level `High`.
186186

187187
| Rule name | Rule state | EDR alerts | Toast notifications |
188188
|---|---|---|---|

0 commit comments

Comments
 (0)