Skip to content

Commit e00446e

Browse files
authored
Merge pull request #1285 from MicrosoftDocs/main
Publish main to live, Thursday 3:30PM PDT, 09/05
2 parents 5ef8cd9 + 3d3d768 commit e00446e

File tree

2 files changed

+20
-4
lines changed

2 files changed

+20
-4
lines changed

defender-endpoint/attack-surface-reduction-rules-reference.md

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -574,6 +574,14 @@ Configuration Manager name: Not yet available
574574

575575
GUID: `33ddedf1-c6e0-47cb-833e-de6133960387`
576576

577+
Advanced hunting action type:
578+
579+
- `AsrSafeModeRebootedAudited`
580+
581+
- `AsrSafeModeRebootBlocked`
582+
583+
- `AsrSafeModeRebootWarnBypassed`
584+
577585
Dependencies: Microsoft Defender Antivirus
578586

579587
### Block untrusted and unsigned processes that run from USB
@@ -611,6 +619,14 @@ Configuration Manager name: Not yet available
611619

612620
GUID: `c0033c00-d16d-4114-a5a0-dc9b3a7d2ceb`
613621

622+
Advanced hunting action type:
623+
624+
- `AsrAbusedSystemToolAudited`
625+
626+
- `AsrAbusedSystemToolBlocked`
627+
628+
- `AsrAbusedSystemToolWarnBypassed`
629+
614630
Dependencies: Microsoft Defender Antivirus
615631

616632
### Block Webshell creation for Servers

defender-endpoint/mtd.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ ms.subservice: onboard
77
ms.author: siosulli
88
author: siosulli
99
ms.localizationpriority: medium
10-
ms.date: 01/28/2024
10+
ms.date: 09/05/2024
1111
manager: deniseb
1212
audience: ITPro
1313
ms.collection:
@@ -101,10 +101,10 @@ While evaluating mobile threat defense with Microsoft Defender for Endpoint, you
101101
This helps reduce potential issues that could arise while rolling out the service. Here are some tests and exit criteria that might help:
102102

103103
- Devices show up in the device inventory list: After successful onboarding of Defender for Endpoint on the mobile device, verify that the device is listed in the Device Inventory in the [security console](https://security.microsoft.com).
104+
<!---
105+
- Run a malware detection test on an Android device: Install any test virus app from the Google play store and verify that it gets detected by Microsoft Defender for Endpoint. Here's an example app that can be used for this test: (We are working on new one, it will be updated soon). Note that on Android Enterprise with a work profile, only the work profile is supported. --->
104106

105-
- Run a malware detection test on an Android device: Install any test virus app from the Google play store and verify that it gets detected by Microsoft Defender for Endpoint. Here's an example app that can be used for this test: [Test virus](https://play.google.com/store/apps/details?id=com.antivirus&hl=en_US&gl=US). Note that on Android Enterprise with a work profile, only the work profile is supported.
106-
107-
- Run a phishing test: Browse to https://smartscreentestratings2.net and verify that it gets blocked by Microsoft Defender for Endpoint. Note that on Android Enterprise with a work profile, only the work profile is supported.
107+
- Run a phishing test: Browse to `https://smartscreentestratings2.net` and verify that it gets blocked by Microsoft Defender for Endpoint. Note that on Android Enterprise with a work profile, only the work profile is supported.
108108

109109
- Alerts appear in dashboard: Verify that alerts for above detection tests appear on the [security console](https://security.microsoft.com).
110110

0 commit comments

Comments
 (0)