Skip to content

Commit fef187d

Browse files
authored
Update attack-surface-reduction-rules-reference.md
1 parent f0909cc commit fef187d

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

defender-endpoint/attack-surface-reduction-rules-reference.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -183,8 +183,8 @@ For rules with the "Rule State" specified:
183183
- ASR rules with \<ASR Rule, Rule State\> combinations are used to surface alerts (toast notifications) on Microsoft Defender for Endpoint only for devices at cloud block level **High**. Devices not at High cloud block level won't generate alerts for any <ASR Rule, Rule State> combinations
184184
- EDR alerts are generated for ASR rules in the specified states, for devices at cloud block level **High+**
185185

186-
| Rule name: | Rule state: | Generates alerts in EDR? <br> (Yes&nbsp;|&nbsp;No) | Generates toast notifications? <br> (Yes&nbsp;|&nbsp;No) |
187-
|---|:---:|:---:|:---:|
186+
| Rule name | Rule state | Generates alerts in EDR? | Generates toast notifications? |
187+
|---|---|---|---|
188188
| | | _Only for devices at cloud block level **High+**_ | _In Block mode only_ and _only for devices at cloud block level **High**_|
189189
|[Block abuse of exploited vulnerable signed drivers](#block-abuse-of-exploited-vulnerable-signed-drivers) | | N | Y |
190190
|[Block Adobe Reader from creating child processes](#block-adobe-reader-from-creating-child-processes) | Block | Y | Y |

0 commit comments

Comments
 (0)