Windows 10: Does Microsoft Defender Exploit Guard Attack Surface Reduction Rules ASR still function...

Discus and support Does Microsoft Defender Exploit Guard Attack Surface Reduction Rules ASR still function... in AntiVirus, Firewalls and System Security to solve the problem; Or is it redundant? If not, it would be nice if this was an option to ensure enhanced security.... Discussion in 'AntiVirus, Firewalls and System Security' started by tutu_312, Mar 14, 2022.

  1. tutu_312 Win User

    Does Microsoft Defender Exploit Guard Attack Surface Reduction Rules ASR still function...


    Or is it redundant? If not, it would be nice if this was an option to ensure enhanced security.

    :)
     
    tutu_312, Mar 14, 2022
    #1
  2. SE_GB Win User

    Windows Defender Device Guard: Attack Surface Reduction

    Dear community,

    I am experiencing a relatively strange behavior using Attack Surface Reduction from the Defender Device Guard.

    As recommended in the baseline security 1809, I did activate the recommended ASR rules; one of them being "Block untrusted and unsigned processes that run from USB" - elaborated

    here
    .

    I did create an unsigned application using Visual studio and C#. Runs fine on the build machine.

    Starting it from a USB drive, Defender Application Guard blocks the application (Code 1121, ID b2b3f03d-6a65-4f7b-a9c7-1c7ef74a9ba4). Intended and expected behavior.

    Copying the previously started (and blocked) application to the local disk and trying to start it from there, it gets blocked again. Not so expected behavior.

    Renaming this executable on the local disk to "xyz_.exe" it is not blocked. Renaming it to its once blocked at USB name, it gets blocked again.

    Does anybody have an idea, if the names of the blocked application are cached in some way or why this behavior occurs?

    Kind regards
     
    SE_GB, Mar 14, 2022
    #2
  3. CCleaner Update Triggers Attack Surface Reduction Rule

    The update to v5.75.8238, CCleaner64.exe triggers an Attack Surface Reduction rule:
    Block credential stealing from the Windows local security authority subsystem (lsass.exe)
    Rule GUID: 9E6C4E1F-7D60-472F-BA1A-A39EF669E4B2

    You won't notice it unless you happen to have ASR in place with Microsoft Defender for Endpoint.
    Here is the event log entry:

    Log Name: Microsoft-Windows-Windows Defender/Operational
    Source: Windows Defender
    Event ID 1121

    Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator.
    For more information please contact your IT administrator.
    ID: 9E6C4E1F-7D60-472F-BA1A-A39EF669E4B2
    Detection time: 2020-12-11T01:57:18.185Z
    User: XXXXXX-XXXXXX\xxxxxxxxxxx

    Path: C:\Windows\System32\lsass.exe
    Process Name: C:\Program Files\CCleaner\CCleaner64.exe
    Security intelligence Version: 1.329.181.0
    Engine Version: 1.1.17700.4
    Product Version: 4.18.2011.6

    A similar message shows up in the GUI also containing:
    "Block credential stealing from the Windows local security authority subsystem (lsass.exe)"
     
    mjohnsonn2, Mar 14, 2022
    #3
  4. Brink Win User

    Does Microsoft Defender Exploit Guard Attack Surface Reduction Rules ASR still function...

    Interpreting Windows Defender Exploit Guard ASR audit alerts

    Source: https://techcommunity.microsoft.com/...ts/ba-p/228366
     
    Brink, Mar 14, 2022
    #4
Thema:

Does Microsoft Defender Exploit Guard Attack Surface Reduction Rules ASR still function...

Loading...
  1. Does Microsoft Defender Exploit Guard Attack Surface Reduction Rules ASR still function... - Similar Threads - Does Microsoft Defender

  2. LSA protection and attack surface rules

    in Windows 10 Gaming
    LSA protection and attack surface rules: Hi,We are implemting defender ssecurity.After putting ASR in audit we start to follow the recommandations.After son time we see the ASR rule "Block credential stealing from the Windows local security authority subsystem lsass.exe" is not applicable.After a long search I found...
  3. Attack Surface Reduction

    in Windows 10 Software and Apps
    Attack Surface Reduction: Windows security keeps blocking some of my scheduled tasks. When I look in the protection log it says This is on a home system that no one else uses https://answers.microsoft.com/en-us/windows/forum/all/attack-surface-reduction/caa697e3-9df7-479e-b477-f27172b5efe5
  4. Attack Surface Reduction

    in Windows 10 Gaming
    Attack Surface Reduction: Windows security keeps blocking some of my scheduled tasks. When I look in the protection log it says This is on a home system that no one else uses https://answers.microsoft.com/en-us/windows/forum/all/attack-surface-reduction/caa697e3-9df7-479e-b477-f27172b5efe5
  5. Question about ASR Rules and Defender for Endpoint P1

    in Windows 10 Gaming
    Question about ASR Rules and Defender for Endpoint P1: I am looking for some clarification on the ASR rule configuration and how it plays into the Defender for Endpoint P1 license. I recently bought a P1 license to test ASR rules on endpoints, configured a GP with ASR rules configured to apply to my endpoint, then applied the...
  6. CCleaner Update Triggers Attack Surface Reduction Rule

    in Windows 10 Software and Apps
    CCleaner Update Triggers Attack Surface Reduction Rule: The update to v5.75.8238, CCleaner64.exe triggers an Attack Surface Reduction rule: Block credential stealing from the Windows local security authority subsystem (lsass.exe) Rule GUID: 9E6C4E1F-7D60-472F-BA1A-A39EF669E4B2 You won't notice it unless you happen to have ASR in...
  7. Microsoft Defender Exploit Guard on Windows 10 Pro

    in AntiVirus, Firewalls and System Security
    Microsoft Defender Exploit Guard on Windows 10 Pro: I've recently found that I'm unbale to access certain websites, e.g. Steam due to the following message in event viewer. Your IT administrator has caused Microsoft Defender Exploit Guard to block a potentially dangerous network connection. Detection time:...
  8. Windows Defender Device Guard: Attack Surface Reduction

    in AntiVirus, Firewalls and System Security
    Windows Defender Device Guard: Attack Surface Reduction: Dear community, I am experiencing a relatively strange behavior using Attack Surface Reduction from the Defender Device Guard. As recommended in the baseline security 1809, I did activate the recommended ASR rules; one of them being "Block untrusted and unsigned processes...
  9. Interpreting Windows Defender Exploit Guard ASR audit alerts

    in Windows 10 News
    Interpreting Windows Defender Exploit Guard ASR audit alerts: In my previous blog, I talked about how you can leverage Windows Defender ATP’s Advanced hunting to monitor Attack Surface Reduction (ASR) alerts in audit mode and dig a little deeper into the potential application compatibility impact of enforcing more rules. Like many app...
  10. Improve your defensive posture with Exploit Guard ASR in Windows 10

    in Windows 10 News
    Improve your defensive posture with Exploit Guard ASR in Windows 10: Windows 10 brings with it a host of new security features – but some of them come with a string attached: you must turn them on! (Security is never easy, is it?) So, why is some assembly required? If there is a security feature that is opt-in, you can bet that there is the...