Files
Scripting/Powershell/PowerShell-collection/Misc/Bootstrap-MicrosoftDefenderConfiguration/Bootstrap-MicrosoftDefenderConfiguration.csv
DistractADD cfddd4fad2 Added Files
2021-07-06 13:16:46 +10:00

1.6 KiB

1RuleIDRuleDescriptionRuleAction
275668C1F-73B5-4CF0-BB93-3ECF5CB7CC84Block Office applications from injecting into other processesEnabled
33B576869-A4EC-4529-8536-B80A7769E899Block Office applications from creating executable contentEnabled
4D4F940AB-401B-4EfC-AADC-AD5F3C50688ABlock Office applications from creating child processesEnabled
5D3E037E1-3EB8-44C8-A917-57927947596DImpede JavaScript and VBScript to launch executablesEnabled
65BEB7EFE-FD9A-4556-801D-275E5FFC04CCBlock execution of potentially obfuscated scriptEnabled
7BE9BA2D9-53EA-4CDC-84E5-9B1EEEE46550Block executable content from email client and webmailEnabled
892E97FA1-2EDF-4476-BDD6-9DD0B4DDDC7BBlock Win32 imports from Macro code in OfficeEnabled
9c1db55ab-c21a-4637-bb3f-a12568109d35Use advanced protection against ransomwareEnabled
109e6c4e1f-7d60-472f-ba1a-a39ef669e4b2Block credential stealing from the Windows local security authority subsystem (lsass.exe)Enabled
11d1e49aac-8f56-4280-b9ba-993a6d77406cBlock process creations originating from PSExec and WMI commandsEnabled
12b2b3f03d-6a65-4f7b-a9c7-1c7ef74a9ba4Block untrusted and unsigned processes that run from USBEnabled
1326190899-1602-49e8-8b27-eb1d0a1ce869Block Office communication applications from creating child processesAuditMode
147674ba52-37eb-4a4f-a9a1-f0f9a1619a2cBlock Adobe Reader from creating child processesEnabled
15e6db77e5-3df2-4cf1-b95a-636979351e5bBlock persistence through WMI event subscriptionEnabled
1601443614-cd74-433a-b99e-2ecdc07bfc25Block executable files from running unless they meet a prevalence age or trusted list criteriaAuditMode