You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-endpoint/attack-surface-reduction-rules-reference.md
+6-6Lines changed: 6 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -183,28 +183,28 @@ For rules with the "Rule State" specified:
183
183
- ASR rules with \<ASR Rule, Rule State\> combinations are used to surface alerts (toast notifications) on Microsoft Defender for Endpoint only for devices at cloud block level **High**. Devices not at High cloud block level won't generate alerts for any <ASR Rule, Rule State> combinations
184
184
- EDR alerts are generated for ASR rules in the specified states, for devices at cloud block level **High+**
|||_Only for devices at cloud block level **High+**_|_In Block mode only_ and _only for devices at cloud block level **High**_|
189
189
|[Block abuse of exploited vulnerable signed drivers](#block-abuse-of-exploited-vulnerable-signed-drivers)|| N | Y |
190
190
|[Block Adobe Reader from creating child processes](#block-adobe-reader-from-creating-child-processes)| Block | Y | Y |
191
191
|[Block all Office applications from creating child processes](#block-all-office-applications-from-creating-child-processes)|| N | Y |
192
-
|[Block credential stealing from the Windows local security authority subsystem (lsass.exe)](#block-credential-stealing-from-the-windows-local-security-authority-subsystem)|| N |Y|
192
+
|[Block credential stealing from the Windows local security authority subsystem (lsass.exe)](#block-credential-stealing-from-the-windows-local-security-authority-subsystem)|| N |N|
193
193
|[Block executable content from email client and webmail](#block-executable-content-from-email-client-and-webmail)|| Y | Y |
194
194
|[Block executable files from running unless they meet a prevalence, age, or trusted list criterion](#block-executable-files-from-running-unless-they-meet-a-prevalence-age-or-trusted-list-criterion)|| N | Y |
195
-
|[Block execution of potentially obfuscated scripts](#block-execution-of-potentially-obfuscated-scripts)| Audit \| Block | Y \| Y | N \| Y |
195
+
|[Block execution of potentially obfuscated scripts](#block-execution-of-potentially-obfuscated-scripts)| Audit | Block | Y | Y | N | Y |
196
196
|[Block JavaScript or VBScript from launching downloaded executable content](#block-javascript-or-vbscript-from-launching-downloaded-executable-content)| Block | Y | Y |
197
197
|[Block Office applications from creating executable content](#block-office-applications-from-creating-executable-content)|| N | Y |
198
198
|[Block Office applications from injecting code into other processes](#block-office-applications-from-injecting-code-into-other-processes)|| N | Y |
199
199
|[Block Office communication application from creating child processes](#block-office-communication-application-from-creating-child-processes)|| N | Y |
200
-
|[Block persistence through WMI event subscription](#block-persistence-through-wmi-event-subscription)| Audit \| Block | Y \| Y | N \| Y |
200
+
|[Block persistence through WMI event subscription](#block-persistence-through-wmi-event-subscription)| Audit | Block | Y | Y | N | Y |
201
201
|[Block process creations originating from PSExec and WMI commands](#block-process-creations-originating-from-psexec-and-wmi-commands)|| N | Y |
202
202
|[Block rebooting machine in Safe Mode (preview)](#block-rebooting-machine-in-safe-mode-preview)|| N | N |
203
-
|[Block untrusted and unsigned processes that run from USB](#block-untrusted-and-unsigned-processes-that-run-from-usb)| Audit \| Block | Y \| Y | N \| Y |
203
+
|[Block untrusted and unsigned processes that run from USB](#block-untrusted-and-unsigned-processes-that-run-from-usb)| Audit | Block | Y | Y | N | Y |
204
204
|[Block use of copied or impersonated system tools (preview)](#block-use-of-copied-or-impersonated-system-tools-preview)|| N | N |
205
205
|[Block Webshell creation for Servers](#block-webshell-creation-for-servers)|| N | N |
206
206
|[Block Win32 API calls from Office macros](#block-win32-api-calls-from-office-macros)|| N | Y |
207
-
|[Use advanced protection against ransomware](#use-advanced-protection-against-ransomware)| Audit \| Block | Y \| Y | N \| Y |
207
+
|[Use advanced protection against ransomware](#use-advanced-protection-against-ransomware)| Audit | Block | Y | Y | N | Y |
0 commit comments