You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The attack surface reduction rules report provides information about the _attack surface reduction rules_ that are applied to devices in your organization. This report also provides information about:
36
+
The attack surface reduction rules report provides information about the attack surface reduction rules that are applied to devices in your organization. This report also provides information about:
37
37
38
38
- detected threats
39
39
- blocked threats
40
40
- devices that aren't configured to use the standard protection rules to block threats
41
41
42
-
Additionally, this report provides an easy-to-use interface that enables you to:
42
+
In addition, this report provides an easy-to-use interface that enables you to:
43
43
44
44
- View threat detections
45
45
- View the configuration of the ASR rules
@@ -59,41 +59,38 @@ For more information about individual attack surface reduction rules, see [Attac
59
59
To access the attack surface reduction rules report in the Microsoft Defender portal, the following permissions are required:
60
60
61
61
| Permission name | Permission type |
62
-
|:---|:---|
62
+
|---|---|
63
63
| View Data | Security operations |
64
64
65
65
> [!IMPORTANT]
66
66
> Microsoft recommends that you use roles with the fewest permissions. This helps improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role.
67
67
68
68
69
-
To Assign these permissions:
70
-
71
-
1. Sign in to the <ahref="https://go.microsoft.com/fwlink/p/?linkid=2077139"target="_blank">Microsoft Defender portal</a> using account with Security administrator or Global administrator role assigned.
69
+
To assign these permissions:
72
70
73
-
1.In the navigation pane, select **Settings**\>**Endpoints**\>**Roles** (under **Permissions**).
71
+
1.Sign in to the [Microsoft Defender portal](https://security.microsoft.com].
74
72
75
-
1. Select the role you'd like to edit.
73
+
2. In the navigation pane, select **Settings**\>**Endpoints**\>**Roles** (under **Permissions**).
76
74
77
-
1. Select **Edit**.
75
+
3. Select the role you'd like to edit, and then select**Edit**.
78
76
79
-
1. In **Edit role**, on the **General** tab, in **Role name**, type a name for the role.
77
+
4. In **Edit role**, on the **General** tab, in **Role name**, type a name for the role.
80
78
81
-
1. In **Description** type a brief summary of the role.
82
-
83
-
1. In **Permissions**, select **View Data**, and under **View Data** select **Security operations**.
79
+
5. In **Description** type a brief summary of the role.
84
80
81
+
6. In **Permissions**, select **View Data**, and under **View Data** select **Security operations**.
85
82
86
83
## Navigate to the attack surface reduction rules report
87
84
88
85
To navigate to the summary cards for the attack surface reduction rules report
89
86
90
-
1. Open **Microsoft Defender XDR**portal.
91
-
1. In the left panel, click**Reports**, and in the main section, under **Reports** select **Security report**.
92
-
1. Scroll down to **Devices** to find the **Attack surface reduction rules** summary cards.
87
+
1. Open the [Microsoft Defender portal](https://security.microsoft.com).
88
+
89
+
2. In the navigation pane, select **Reports**. In the main section, under **Reports**, select **Security report**.
93
90
94
-
The summary report cards for ASR rules are shown in the following figure.
91
+
3. Scroll down to **Devices** to find the **Attack surface reduction rules** summary cards. The summary report cards for ASR rules resemble the following image:
95
92
96
-
>:::image type="content" source="media/attack-surface-reduction-rules-report-summary.png" alt-text="Shows the ASR rules report summary cards" lightbox="media/attack-surface-reduction-rules-report-summary.png":::
93
+
:::image type="content" source="media/attack-surface-reduction-rules-report-summary.png" alt-text="Shows the ASR rules report summary cards" lightbox="media/attack-surface-reduction-rules-report-summary.png":::
97
94
98
95
## ASR rules report summary cards
99
96
@@ -104,31 +101,29 @@ The ASR rules report summary is divided into two cards:
104
101
105
102
### ASR rules detections summary card
106
103
107
-
Shows a summary of the number of detected threats blocked by ASR rules.
104
+
The ASR rules detections summary card shows a summary of the number of detected threats blocked by ASR rules. This card includes two action buttons:
108
105
109
-
Provides two 'action' buttons:
110
-
111
-
- View detections - opens the **Attack surface reduction rules** > main **Detections** tab
112
-
- Add exclusions - Opens the **Attack surface reduction rules** > main **Exclusions** tab
106
+
-**View detections**: Opens the **Detections** tab
107
+
-**Add exclusions**: Opens the **Exclusions** tab
113
108
114
109
:::image type="content" source="media/attack-surface-reduction-rules-report-main-detections-card.png" alt-text="Screenshot that shows the ASR rules report summary detections card." lightbox="media/attack-surface-reduction-rules-report-main-detections-card.png":::
115
110
116
-
Clicking on the **ASR rules detections** link at the top of the card also opens the main [Attack surface reduction rules Detections tab](#attack-surface-reduction-rules-main-detections-tab).
111
+
Selecting the **ASR rules detections** link at the top of the card also opens the main [Attack surface reduction rules Detections tab](#attack-surface-reduction-rules-main-detections-tab).
117
112
118
113
### ASR rules configuration summary card
119
114
120
-
**The top section** focuses on three recommended rules, which protect against common attack techniques. This card shows current-state information about the computers in your organization that have the following [Three \(ASR\) standard protection rules](#simplified-standard-protection-option) set in **Block mode**, **Audit mode**, or **off** (not configured).The **Protect devices** button will show full configuration details for only the three rules; customers can quickly take action to enable these rules.
115
+
The top section focuses on three recommended rules, which protect against common attack techniques. This card shows current-state information about the computers in your organization that have the following [Three \(ASR\) standard protection rules](#simplified-standard-protection-option) set in **Block mode**, **Audit mode**, or **off** (not configured).The **Protect devices** button will show full configuration details for only the three rules; customers can quickly take action to enable these rules.
121
116
122
-
**The bottom section** surfaces six rules based on the number of unprotected devices per rule. The "View configuration" button surfaces all configuration details for all ASR rules. The "Add exclusion" button shows the add exclusion page with all detected file/process names listed for Security Operation Center (SOC) to evaluate. The **Add exclusion** page is linked to Microsoft Intune.
117
+
The bottom section surfaces six rules based on the number of unprotected devices per rule. The "View configuration" button surfaces all configuration details for all ASR rules. The "Add exclusion" button shows the add exclusion page with all detected file/process names listed for Security Operation Center (SOC) to evaluate. The **Add exclusion** page is linked to Microsoft Intune.
:::image type="content" source="media/attack-surface-reduction-rules-report-main-detections-configuration-card.png" alt-text="Shows the ASR rules report summary configuration card." lightbox="media/attack-surface-reduction-rules-report-main-detections-configuration-card.png":::
130
125
131
-
Clicking on the **ASR rules configuration** link at the top of the card also opens the main [Attack surface reduction rules Configuration tab](#attack-surface-reduction-rules-main-configuration-tab).
126
+
Selecting the **ASR rules configuration** link at the top of the card also opens the main [Attack surface reduction rules Configuration tab](#attack-surface-reduction-rules-main-configuration-tab).
132
127
133
128
#### Simplified standard protection option
134
129
@@ -141,15 +136,17 @@ The configuration summary card provides a button to **Protect devices** with the
141
136
To enable the three standard protection rules:
142
137
143
138
1. Select **Protect devices**. The main **Configuration** tab opens.
144
-
1. On the **Configuration** tab, **Basic rules** automatically toggles from **All rules** to **Standard protection rules** enabled.
145
-
1. In the **Devices** list, select the devices for which you want the standard protection rules to apply, and then select **Save**.
139
+
140
+
2. On the **Configuration** tab, **Basic rules** automatically toggles from **All rules** to **Standard protection rules** enabled.
141
+
142
+
3. In the **Devices** list, select the devices for which you want the standard protection rules to apply, and then select **Save**.
-**View configuration**: Opens the **Configuration** tab.
147
+
-**Add exclusions**: Opens the **Exclusions** tab.
151
148
152
-
Clicking on the **ASR rules configuration** link at the top of the card also opens the main [Attack surface reduction rules Configuration tab](#attack-surface-reduction-rules-main-configuration-tab).
149
+
Selecting the **ASR rules configuration** link at the top of the card also opens the main [Attack surface reduction rules Configuration tab](#attack-surface-reduction-rules-main-configuration-tab).
153
150
154
151
## Attack surface reduction rules main tabs
155
152
@@ -185,11 +182,11 @@ Filtering provides a way for you to specify what results are returned:
185
182
186
183
### Attack surface reduction rules main detections tab
187
184
188
-
-**Audit Detections** Shows how many threat detections were captured by rules set in _Audit_ mode.
189
-
-**Blocked Detections** Shows how many threat detections were blocked by rules set in _Block_ mode.
190
-
-**Large, consolidated graph** Shows blocked and audited detections.
185
+
-**Audit Detections**: Shows how many threat detections were captured by rules set in _Audit_ mode.
186
+
-**Blocked Detections**: Shows how many threat detections were blocked by rules set in _Block_ mode.
187
+
-**Large, consolidated graph**: Shows blocked and audited detections.
191
188
192
-
>:::image type="content" source="media/attack-surface-reduction-rules-report-main-detections-tab.png" alt-text="Shows the ASR rules report main detections tab, with _Audit detections_ and _Blocked detections_ outlined." lightbox="media/attack-surface-reduction-rules-report-main-detections-tab.png":::
189
+
:::image type="content" source="media/attack-surface-reduction-rules-report-main-detections-tab.png" alt-text="Shows the ASR rules report main detections tab, with _Audit detections_ and _Blocked detections_ outlined." lightbox="media/attack-surface-reduction-rules-report-main-detections-tab.png":::
193
190
194
191
The graphs provide detection data over the displayed date range, with the capability to hover over a specific location to gather date-specific information.
195
192
@@ -256,22 +253,21 @@ These elements are shown in the following figure.
256
253
To enable ASR rules:
257
254
258
255
1. Under **Device**, select the device or devices for which you want to apply ASR rules.
259
-
1. In the flyout window, verify your selections and then select **Add to policy**.
260
256
261
-
The **Configuration** tab and _add rule_ flyout are shown in the following image.
257
+
2. In the flyout window, verify your selections and then select **Add to policy**. The **Configuration** tab and **add rule** flyout are shown in the following image.
262
258
263
-
> [NOTE!]
264
-
> If you have devices that require that different ASR rules be applied, you should configure those devices individually.
259
+
:::image type="content" source="media/attack-surface-reduction-rules-report-configuration-add-to-policy.png" alt-text="Shows the ASR rules fly-out to add ASR rules to devices" lightbox="media/attack-surface-reduction-rules-report-configuration-add-to-policy.png":::
265
260
266
-
>:::image type="content" source="media/attack-surface-reduction-rules-report-configuration-add-to-policy.png" alt-text="Shows the ASR rules fly-out to add ASR rules to devices" lightbox="media/attack-surface-reduction-rules-report-configuration-add-to-policy.png":::
261
+
> [NOTE!]
262
+
> If you have devices that require that different ASR rules be applied, you should configure those devices individually.
The **Add exclusions** tab presents a ranked list of detections by file name and provides a method to configure exclusions. By default, **Add exclusions** information is listed for three fields:
271
267
272
-
-**File name** The name of the file that triggered the ASR rules event.
273
-
-**Detections** The total number of detected events for named file. Individual devices can trigger multiple ASR rules events.
274
-
-**Devices** The number of devices on which the detection occurred.
268
+
-**File name**: The name of the file that triggered the ASR rules event.
269
+
-**Detections**: The total number of detected events for named file. Individual devices can trigger multiple ASR rules events.
270
+
-**Devices**: The number of devices on which the detection occurred.
275
271
276
272
>:::image type="content" source="media/attack-surface-reduction-rules-report-exclusion-tab.png" alt-text="Shows the ASR rules report add exclusions tab" lightbox="media/attack-surface-reduction-rules-report-exclusion-tab.png":::
277
273
@@ -290,7 +286,7 @@ The Add exclusion page has two buttons for actions that can be used on any detec
290
286
-**Add exclusion** which will open Microsoft Intune ASR policy page. For more information, see: [Intune](enable-attack-surface-reduction.md) in "Enable ASR rules alternate configuration methods."
291
287
-**Get exclusion paths** which will download file paths in a csv format
292
288
293
-
>:::image type="content" source="media/attack-surface-reduction-rules-report-main-add-exclusions-flyout.png" alt-text="Shows the ASR rules report add exclusions tab flyout impact summary" lightbox="media/attack-surface-reduction-rules-report-main-add-exclusions-flyout.png":::
289
+
:::image type="content" source="media/attack-surface-reduction-rules-report-main-add-exclusions-flyout.png" alt-text="Shows the ASR rules report add exclusions tab flyout impact summary" lightbox="media/attack-surface-reduction-rules-report-main-add-exclusions-flyout.png":::
294
290
295
291
## See also
296
292
@@ -301,4 +297,5 @@ The Add exclusion page has two buttons for actions that can be used on any detec
0 commit comments