1.6 KiB
1.6 KiB
| 1 | RuleID | RuleDescription | RuleAction |
|---|---|---|---|
| 2 | 75668C1F-73B5-4CF0-BB93-3ECF5CB7CC84 | Block Office applications from injecting into other processes | Enabled |
| 3 | 3B576869-A4EC-4529-8536-B80A7769E899 | Block Office applications from creating executable content | Enabled |
| 4 | D4F940AB-401B-4EfC-AADC-AD5F3C50688A | Block Office applications from creating child processes | Enabled |
| 5 | D3E037E1-3EB8-44C8-A917-57927947596D | Impede JavaScript and VBScript to launch executables | Enabled |
| 6 | 5BEB7EFE-FD9A-4556-801D-275E5FFC04CC | Block execution of potentially obfuscated script | Enabled |
| 7 | BE9BA2D9-53EA-4CDC-84E5-9B1EEEE46550 | Block executable content from email client and webmail | Enabled |
| 8 | 92E97FA1-2EDF-4476-BDD6-9DD0B4DDDC7B | Block Win32 imports from Macro code in Office | Enabled |
| 9 | c1db55ab-c21a-4637-bb3f-a12568109d35 | Use advanced protection against ransomware | Enabled |
| 10 | 9e6c4e1f-7d60-472f-ba1a-a39ef669e4b2 | Block credential stealing from the Windows local security authority subsystem (lsass.exe) | Enabled |
| 11 | d1e49aac-8f56-4280-b9ba-993a6d77406c | Block process creations originating from PSExec and WMI commands | Enabled |
| 12 | b2b3f03d-6a65-4f7b-a9c7-1c7ef74a9ba4 | Block untrusted and unsigned processes that run from USB | Enabled |
| 13 | 26190899-1602-49e8-8b27-eb1d0a1ce869 | Block Office communication applications from creating child processes | AuditMode |
| 14 | 7674ba52-37eb-4a4f-a9a1-f0f9a1619a2c | Block Adobe Reader from creating child processes | Enabled |
| 15 | e6db77e5-3df2-4cf1-b95a-636979351e5b | Block persistence through WMI event subscription | Enabled |
| 16 | 01443614-cd74-433a-b99e-2ecdc07bfc25 | Block executable files from running unless they meet a prevalence age or trusted list criteria | AuditMode |