Windows 10: Windows Defender Device Guard: Attack Surface Reduction

Discus and support Windows Defender Device Guard: Attack Surface Reduction in AntiVirus, Firewalls and System Security to solve the problem; Dear community, I am experiencing a relatively strange behavior using Attack Surface Reduction from the Defender Device Guard. As recommended in the... Discussion in 'AntiVirus, Firewalls and System Security' started by SE_GB, Feb 19, 2020.

  1. SE_GB Win User

    Windows Defender Device Guard: Attack Surface Reduction


    Dear community,


    I am experiencing a relatively strange behavior using Attack Surface Reduction from the Defender Device Guard.

    As recommended in the baseline security 1809, I did activate the recommended ASR rules; one of them being "Block untrusted and unsigned processes that run from USB" - elaboratedhere.


    I did create an unsigned application using Visual studio and C#. Runs fine on the build machine.

    Starting it from a USB drive, Defender Application Guard blocks the application Code 1121, ID b2b3f03d-6a65-4f7b-a9c7-1c7ef74a9ba4. Intended and expected behavior.


    Copying the previously started and blocked application to the local disk and trying to start it from there, it gets blocked again. Not so expected behavior.

    Renaming this executable on the local disk to "xyz_.exe" it is not blocked. Renaming it to its once blocked at USB name, it gets blocked again.


    Does anybody have an idea, if the names of the blocked application are cached in some way or why this behavior occurs?


    Kind regards

    SE_GB

    :)
     
    SE_GB, Feb 19, 2020
    #1
  2. Brink Win User

    Windows Defender Application Guard extensions for Chrome and Firefox



    Source: https://www.microsoft.com/security/b...sed-isolation/
     
    Brink, Feb 19, 2020
    #2
  3. Brink Win User
    Windows Defender Application Guard extensions for Chrome and Firefox


    Source: https://www.microsoft.com/security/b...sed-isolation/
     
    Brink, Feb 19, 2020
    #3
  4. Rob Koch Win User

    Windows Defender Device Guard: Attack Surface Reduction

    WD ASR : Block executable files from running unless they meet a prevalence, age, or trusted list criteria.

    These forums are for consumers, so your question about an Attack Surface Reduction rule that's typically managed via Windows Defender Advanced Threat Protection (Windows Defender ATP) is out of scope here. You should be asking this in the appropriate TechNet
    forums related to that product.

    That said, I assume you found the following document that provides what little information seems to exist in the public domain? I assume you'd need to know how to manage the prevalence, age, trusted list or exclusion list items within either WD ATP or enterprise
    policies in order to configure them for the rule to work.

    Rob

    Use attack surface reduction rules to prevent malware infection Microsoft
    Docs


    Rule: Block executable files from running unless they meet a prevalence, age, or trusted list criteria


    This rule blocks the following file types from being run or launched unless they meet prevalence or age criteria set by admins, or they are in a trusted list or exclusion list:

    • Executable files (such as .exe, .dll, or .scr)

    Note

    You must
    enable cloud-delivered protection
    to use this rule.
     
    Rob Koch, Feb 19, 2020
    #4
Thema:

Windows Defender Device Guard: Attack Surface Reduction

Loading...
  1. Windows Defender Device Guard: Attack Surface Reduction - Similar Threads - Defender Device Guard

  2. Attack Surface Reduction

    in Windows 10 Software and Apps
    Attack Surface Reduction: Windows security keeps blocking some of my scheduled tasks. When I look in the protection log it says This is on a home system that no one else uses https://answers.microsoft.com/en-us/windows/forum/all/attack-surface-reduction/caa697e3-9df7-479e-b477-f27172b5efe5
  3. Attack Surface Reduction

    in Windows 10 Gaming
    Attack Surface Reduction: Windows security keeps blocking some of my scheduled tasks. When I look in the protection log it says This is on a home system that no one else uses https://answers.microsoft.com/en-us/windows/forum/all/attack-surface-reduction/caa697e3-9df7-479e-b477-f27172b5efe5
  4. Windows Defender: Attack Surface Reduction - No Events in EventLog for some blocked actions

    in AntiVirus, Firewalls and System Security
    Windows Defender: Attack Surface Reduction - No Events in EventLog for some blocked actions: I have some ASR rules activated set to Block for my clients, like "Block process creations originating from PSExec and WMI commands" or "Block JavaScript or VBScript from launching downloaded executable content".While testing the rules it seems like, they work as intended but...
  5. Does Microsoft Defender Exploit Guard Attack Surface Reduction Rules ASR still function...

    in AntiVirus, Firewalls and System Security
    Does Microsoft Defender Exploit Guard Attack Surface Reduction Rules ASR still function...: Or is it redundant? If not, it would be nice if this was an option to ensure enhanced security. https://answers.microsoft.com/en-us/protect/forum/all/does-microsoft-defender-exploit-guard-attack/816b13d2-5f7b-4c9a-9065-d95f4acbb1aa
  6. CCleaner Update Triggers Attack Surface Reduction Rule

    in Windows 10 Software and Apps
    CCleaner Update Triggers Attack Surface Reduction Rule: The update to v5.75.8238, CCleaner64.exe triggers an Attack Surface Reduction rule: Block credential stealing from the Windows local security authority subsystem (lsass.exe) Rule GUID: 9E6C4E1F-7D60-472F-BA1A-A39EF669E4B2 You won't notice it unless you happen to have ASR in...
  7. Windows Defender Application Guard

    in AntiVirus, Firewalls and System Security
    Windows Defender Application Guard: Windows Defender Application Guard is listed on my windows features in control Panel but it's out of colour and when I try to turn on the feature it says my device configuration doesn't support it....
  8. Windows Defender Application Guard

    in AntiVirus, Firewalls and System Security
    Windows Defender Application Guard: Hi, could you please advise if need to install Hypervisor feature in Windows 10 devices install and configure Windows Defender Application Guard? https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-guard/reqs-wd-app-guard...
  9. Windows Defender Application Guard

    in AntiVirus, Firewalls and System Security
    Windows Defender Application Guard: I found the instructions for installing and setting up Application Guard using GPO. We have moved our entire infrastructure to Microsoft 365 in the cloud so how do you set up Application Guard using Intune policies?...
  10. Windows Defender Application Guard?

    in AntiVirus, Firewalls and System Security
    Windows Defender Application Guard?: I noticed a setting to enable Windows Defender Application Guard in Edge but can't find discussion of it on the forum. Has anyone used this feature and found it useful? 128727