Skip to content

Commit 791b1c8

Browse files
committed
Update troubleshoot-asr.md
1 parent 1968dc5 commit 791b1c8

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

defender-endpoint/troubleshoot-asr.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -68,7 +68,7 @@ Follow these instructions in [Use the demo tool to see how attack surface reduct
6868

6969
1. Enable audit mode for the specific rule you want to test. Use Group Policy to set the rule to `Audit mode` (value: `2`) as described in [Enable attack surface reduction rules](enable-attack-surface-reduction.md). Audit mode allows the rule to report the file or process, but allows it to run.
7070

71-
2. Perform the activity that is causing an issue (for example, open or execute the file or process that should be blocked but is being allowed).
71+
2. Perform the activity that is causing an issue. For example, open the file or run the process that should be blocked, but is allowed.
7272

7373
3. [Review the attack surface reduction rule event logs](attack-surface-reduction.md) to see if the rule would block the file or process if the rule were set to `Enabled`.
7474

0 commit comments

Comments
 (0)