Skip to content

Commit

Permalink
Add items to detect Defender settings configured by Intune
Browse files Browse the repository at this point in the history
  • Loading branch information
0x6d69636b committed Dec 13, 2022
1 parent 3621781 commit dd76b5a
Show file tree
Hide file tree
Showing 2 changed files with 48 additions and 8 deletions.
28 changes: 24 additions & 4 deletions lists/finding_list_0x6d69636b_machine.csv
Original file line number Diff line number Diff line change
Expand Up @@ -195,47 +195,67 @@ ID,Category,Name,Method,MethodArgument,RegistryPath,RegistryItem,ClassName,Names
1800,"Microsoft Defender Antivirus","Turn off Microsoft Defender Antivirus",Registry,,"HKLM:\Software\Policies\Microsoft\Windows Defender",DisableAntiSpyware,,,,0,0,=,Medium
1801,"Microsoft Defender Antivirus","Configure detection for potentially unwanted applications",Registry,,"HKLM:\Software\Policies\Microsoft\Windows Defender",PUAProtection,,,,0,1,>=,Medium
1806,"Microsoft Defender Antivirus","Exclusions: Extension Exclusions (Policy)",Registry,,"HKLM:\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions",Exclusions_Extensions,,,,,,=,Medium
1807,"Microsoft Defender Antivirus","Exclusions: List Extension Exclusions",MpPreferenceExclusion,ExclusionExtension,,,,,,,,=,Medium
1813,"Microsoft Defender Antivirus","Exclusions: Extension Exclusions (Intune)",Registry,,"HKLM:\SOFTWARE\Policies\Microsoft\Windows Defender\Policy Manager",ExcludedExtensions,,,,,,=,Medium
1807,"Microsoft Defender Antivirus","Exclusions: Extension Exclusions",MpPreferenceExclusion,ExclusionExtension,,,,,,,,=,Medium
1808,"Microsoft Defender Antivirus","Exclusions: Path Exclusions (Policy)",Registry,,"HKLM:\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions",Exclusions_Paths,,,,,,=,Medium
1809,"Microsoft Defender Antivirus","Exclusions: List Path Exclusions",MpPreferenceExclusion,ExclusionPath,,,,,,,,=,Medium
1814,"Microsoft Defender Antivirus","Exclusions: Path Exclusions (Intune)",Registry,,"HKLM:\SOFTWARE\Policies\Microsoft\Windows Defender\Policy Manager",ExcludedPaths,,,,,,=,Medium
1809,"Microsoft Defender Antivirus","Exclusions: Path Exclusions",MpPreferenceExclusion,ExclusionPath,,,,,,,,=,Medium
1810,"Microsoft Defender Antivirus","Exclusions: Process Exclusions (Policy)",Registry,,"HKLM:\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions",Exclusions_Processes,,,,,,=,Medium
1811,"Microsoft Defender Antivirus","Exclusions: List Process Exclusions",MpPreferenceExclusion,ExclusionProcess,,,,,,,,=,Medium
1815,"Microsoft Defender Antivirus","Exclusions: Process Exclusions (Intune)",Registry,,"HKLM:\SOFTWARE\Policies\Microsoft\Windows Defender\Policy Manager",ExcludedProcesses,,,,,,=,Medium
1811,"Microsoft Defender Antivirus","Exclusions: Process Exclusions",MpPreferenceExclusion,ExclusionProcess,,,,,,,,=,Medium
1812,"Microsoft Defender Antivirus","Enable sandboxing for Microsoft Defender Antivirus",Registry,,"HKLM:\SYSTEM\CurrentControlSet\Control\Session Manager\Environment",MP_FORCE_USE_SANDBOX,,,,0,1,=,Medium
1900,"Microsoft Defender Exploit Guard","Attack Surface Reduction rules",Registry,,"HKLM:\Software\Policies\Microsoft\Windows Defender\Windows Defender Exploit Guard\ASR",ExploitGuard_ASR_Rules,,,,0,1,=,Medium
1901,"Microsoft Defender Exploit Guard","ASR: Block executable content from email client and webmail (Policy)",Registry,,"HKLM:\Software\Policies\Microsoft\Windows Defender\Windows Defender Exploit Guard\ASR\rules",be9ba2d9-53ea-4cdc-84e5-9b1eeee46550,,,,0,1,=,Medium
1916,"Microsoft Defender Exploit Guard","ASR: Block executable content from email client and webmail",MpPreferenceAsr,be9ba2d9-53ea-4cdc-84e5-9b1eeee46550,,,,,,0,1,=,Medium
1933,"Microsoft Defender Exploit Guard","ASR: Block executable content from email client and webmail (Intune)",Registry,be9ba2d9-53ea-4cdc-84e5-9b1eeee46550,"HKLM:\Software\Policies\Microsoft\Windows Defender\Policy Manager",ASRRules,,,,0,1,=,Medium
1902,"Microsoft Defender Exploit Guard","ASR: Block all Office applications from creating child processes (Policy)",Registry,,"HKLM:\Software\Policies\Microsoft\Windows Defender\Windows Defender Exploit Guard\ASR\rules",d4f940ab-401b-4efc-aadc-ad5f3c50688a,,,,0,1,=,Medium
1917,"Microsoft Defender Exploit Guard","ASR: Block all Office applications from creating child processes",MpPreferenceAsr,d4f940ab-401b-4efc-aadc-ad5f3c50688a,,,,,,0,1,=,Medium
1934,"Microsoft Defender Exploit Guard","ASR: Block all Office applications from creating child processes (Intune)",Registry,d4f940ab-401b-4efc-aadc-ad5f3c50688a,"HKLM:\Software\Policies\Microsoft\Windows Defender\Policy Manager",ASRRules,,,,0,1,=,Medium
1903,"Microsoft Defender Exploit Guard","ASR: Block Office applications from creating executable content (Policy)",Registry,,"HKLM:\Software\Policies\Microsoft\Windows Defender\Windows Defender Exploit Guard\ASR\rules",3b576869-a4ec-4529-8536-b80a7769e899,,,,0,1,=,Medium
1918,"Microsoft Defender Exploit Guard","ASR: Block Office applications from creating executable content",MpPreferenceAsr,3b576869-a4ec-4529-8536-b80a7769e899,,,,,,0,1,=,Medium
1935,"Microsoft Defender Exploit Guard","ASR: Block Office applications from creating executable content (Intune)",Registry,3b576869-a4ec-4529-8536-b80a7769e899,"HKLM:\Software\Policies\Microsoft\Windows Defender\Policy Manager",ASRRules,,,,0,1,=,Medium
1904,"Microsoft Defender Exploit Guard","ASR: Block Office applications from injecting code into other processes (Policy)",Registry,,"HKLM:\Software\Policies\Microsoft\Windows Defender\Windows Defender Exploit Guard\ASR\rules",75668c1f-73b5-4cf0-bb93-3ecf5cb7cc84,,,,0,1,=,Medium
1919,"Microsoft Defender Exploit Guard","ASR: Block Office applications from injecting code into other processes",MpPreferenceAsr,75668c1f-73b5-4cf0-bb93-3ecf5cb7cc84,,,,,,0,1,=,Medium
1936,"Microsoft Defender Exploit Guard","ASR: Block Office applications from injecting code into other processes (Intune)",Registry,75668c1f-73b5-4cf0-bb93-3ecf5cb7cc84,"HKLM:\Software\Policies\Microsoft\Windows Defender\Policy Manager",ASRRules,,,,0,1,=,Medium
1905,"Microsoft Defender Exploit Guard","ASR: Block JavaScript or VBScript from launching downloaded executable content (Policy)",Registry,,"HKLM:\Software\Policies\Microsoft\Windows Defender\Windows Defender Exploit Guard\ASR\rules",d3e037e1-3eb8-44c8-a917-57927947596d,,,,0,1,=,Medium
1920,"Microsoft Defender Exploit Guard","ASR: Block JavaScript or VBScript from launching downloaded executable content",MpPreferenceAsr,d3e037e1-3eb8-44c8-a917-57927947596d,,,,,,0,1,=,Medium
1937,"Microsoft Defender Exploit Guard","ASR: Block JavaScript or VBScript from launching downloaded executable content (Intune)",Registry,d3e037e1-3eb8-44c8-a917-57927947596d,"HKLM:\Software\Policies\Microsoft\Windows Defender\Policy Manager",ASRRules,,,,0,1,=,Medium
1906,"Microsoft Defender Exploit Guard","ASR: Block execution of potentially obfuscated scripts (Policy)",Registry,,"HKLM:\Software\Policies\Microsoft\Windows Defender\Windows Defender Exploit Guard\ASR\rules",5beb7efe-fd9a-4556-801d-275e5ffc04cc,,,,0,1,=,Medium
1921,"Microsoft Defender Exploit Guard","ASR: Block execution of potentially obfuscated scripts",MpPreferenceAsr,5beb7efe-fd9a-4556-801d-275e5ffc04cc,,,,,,0,1,=,Medium
1938,"Microsoft Defender Exploit Guard","ASR: Block execution of potentially obfuscated scripts (Intune)",Registry,5beb7efe-fd9a-4556-801d-275e5ffc04cc,"HKLM:\Software\Policies\Microsoft\Windows Defender\Policy Manager",ASRRules,,,,0,1,=,Medium
1907,"Microsoft Defender Exploit Guard","ASR: Block Win32 API calls from Office macros (Policy)",Registry,,"HKLM:\Software\Policies\Microsoft\Windows Defender\Windows Defender Exploit Guard\ASR\rules",92e97fa1-2edf-4476-bdd6-9dd0b4dddc7b,,,,0,1,=,Medium
1922,"Microsoft Defender Exploit Guard","ASR: Block Win32 API calls from Office macros",MpPreferenceAsr,92e97fa1-2edf-4476-bdd6-9dd0b4dddc7b,,,,,,0,1,=,Medium
1939,"Microsoft Defender Exploit Guard","ASR: Block Win32 API calls from Office macros (Intune)",Registry,92e97fa1-2edf-4476-bdd6-9dd0b4dddc7b,"HKLM:\Software\Policies\Microsoft\Windows Defender\Policy Manager",ASRRules,,,,0,1,=,Medium
1908,"Microsoft Defender Exploit Guard","ASR: Block executable files from running unless they meet a prevalence, age, or trusted list criterion (Policy)",Registry,,"HKLM:\Software\Policies\Microsoft\Windows Defender\Windows Defender Exploit Guard\ASR\rules",01443614-cd74-433a-b99e-2ecdc07bfc25,,,,0,1,=,Medium
1923,"Microsoft Defender Exploit Guard","ASR: Block executable files from running unless they meet a prevalence, age, or trusted list criterion",MpPreferenceAsr,01443614-cd74-433a-b99e-2ecdc07bfc25,,,,,,0,1,=,Medium
1940,"Microsoft Defender Exploit Guard","ASR: Block executable files from running unless they meet a prevalence, age, or trusted list criterion (Intune)",Registry,01443614-cd74-433a-b99e-2ecdc07bfc25,"HKLM:\Software\Policies\Microsoft\Windows Defender\Policy Manager",ASRRules,,,,0,1,=,Medium
1909,"Microsoft Defender Exploit Guard","ASR: Use advanced protection against ransomware (Policy)",Registry,,"HKLM:\Software\Policies\Microsoft\Windows Defender\Windows Defender Exploit Guard\ASR\rules",c1db55ab-c21a-4637-bb3f-a12568109d35,,,,0,1,=,Medium
1924,"Microsoft Defender Exploit Guard","ASR: Use advanced protection against ransomware",MpPreferenceAsr,c1db55ab-c21a-4637-bb3f-a12568109d35,,,,,,0,1,=,Medium
1941,"Microsoft Defender Exploit Guard","ASR: Use advanced protection against ransomware (Intune)",Registry,c1db55ab-c21a-4637-bb3f-a12568109d35,"HKLM:\Software\Policies\Microsoft\Windows Defender\Policy Manager",ASRRules,,,,0,1,=,Medium
1910,"Microsoft Defender Exploit Guard","ASR: Block credential stealing from the Windows local security authority subsystem (lsass.exe) (Policy)",Registry,,"HKLM:\Software\Policies\Microsoft\Windows Defender\Windows Defender Exploit Guard\ASR\rules",9e6c4e1f-7d60-472f-ba1a-a39ef669e4b2,,,,0,1,=,Medium
1925,"Microsoft Defender Exploit Guard","ASR: Block credential stealing from the Windows local security authority subsystem (lsass.exe)",MpPreferenceAsr,9e6c4e1f-7d60-472f-ba1a-a39ef669e4b2,,,,,,0,1,=,Medium
1942,"Microsoft Defender Exploit Guard","ASR: Block credential stealing from the Windows local security authority subsystem (lsass.exe) (Intune)",Registry,9e6c4e1f-7d60-472f-ba1a-a39ef669e4b2,"HKLM:\Software\Policies\Microsoft\Windows Defender\Policy Manager",ASRRules,,,,0,1,=,Medium
1911,"Microsoft Defender Exploit Guard","ASR: Block process creations originating from PSExec and WMI commands (Policy)",Registry,,"HKLM:\Software\Policies\Microsoft\Windows Defender\Windows Defender Exploit Guard\ASR\rules",d1e49aac-8f56-4280-b9ba-993a6d77406c,,,,0,1,=,Medium
1926,"Microsoft Defender Exploit Guard","ASR: Block process creations originating from PSExec and WMI commands",MpPreferenceAsr,d1e49aac-8f56-4280-b9ba-993a6d77406c,,,,,,0,1,=,Medium
1943,"Microsoft Defender Exploit Guard","ASR: Block process creations originating from PSExec and WMI commands (Intune)",Registry,d1e49aac-8f56-4280-b9ba-993a6d77406c,"HKLM:\Software\Policies\Microsoft\Windows Defender\Policy Manager",ASRRules,,,,0,1,=,Medium
1912,"Microsoft Defender Exploit Guard","ASR: Block untrusted and unsigned processes that run from USB (Policy)",Registry,,"HKLM:\Software\Policies\Microsoft\Windows Defender\Windows Defender Exploit Guard\ASR\rules",b2b3f03d-6a65-4f7b-a9c7-1c7ef74a9ba4,,,,0,1,=,Medium
1927,"Microsoft Defender Exploit Guard","ASR: Block untrusted and unsigned processes that run from USB",MpPreferenceAsr,b2b3f03d-6a65-4f7b-a9c7-1c7ef74a9ba4,,,,,,0,1,=,Medium
1944,"Microsoft Defender Exploit Guard","ASR: Block untrusted and unsigned processes that run from USB (Intune)",Registry,b2b3f03d-6a65-4f7b-a9c7-1c7ef74a9ba4,"HKLM:\Software\Policies\Microsoft\Windows Defender\Policy Manager",ASRRules,,,,0,1,=,Medium
1913,"Microsoft Defender Exploit Guard","ASR: Block Office communication application from creating child processes (Policy)",Registry,,"HKLM:\Software\Policies\Microsoft\Windows Defender\Windows Defender Exploit Guard\ASR\rules",26190899-1602-49e8-8b27-eb1d0a1ce869,,,,0,1,=,Medium
1928,"Microsoft Defender Exploit Guard","ASR: Block Office communication application from creating child processes",MpPreferenceAsr,26190899-1602-49e8-8b27-eb1d0a1ce869,,,,,,0,1,=,Medium
1945,"Microsoft Defender Exploit Guard","ASR: Block Office communication application from creating child processes (Intune)",Registry,26190899-1602-49e8-8b27-eb1d0a1ce869,"HKLM:\Software\Policies\Microsoft\Windows Defender\Policy Manager",ASRRules,,,,0,1,=,Medium
1914,"Microsoft Defender Exploit Guard","ASR: Block Adobe Reader from creating child processes (Policy)",Registry,,"HKLM:\Software\Policies\Microsoft\Windows Defender\Windows Defender Exploit Guard\ASR\rules",7674ba52-37eb-4a4f-a9a1-f0f9a1619a2c,,,,0,1,=,Medium
1929,"Microsoft Defender Exploit Guard","ASR: Block Adobe Reader from creating child processes",MpPreferenceAsr,7674ba52-37eb-4a4f-a9a1-f0f9a1619a2c,,,,,,0,1,=,Medium
1946,"Microsoft Defender Exploit Guard","ASR: Block Adobe Reader from creating child processes (Intune)",Registry,7674ba52-37eb-4a4f-a9a1-f0f9a1619a2c,"HKLM:\Software\Policies\Microsoft\Windows Defender\Policy Manager",ASRRules,,,,0,1,=,Medium
1915,"Microsoft Defender Exploit Guard","ASR: Block persistence through WMI event subscription (Policy)",Registry,,"HKLM:\Software\Policies\Microsoft\Windows Defender\Windows Defender Exploit Guard\ASR\rules",e6db77e5-3df2-4cf1-b95a-636979351e5b,,,,0,1,=,Medium
1930,"Microsoft Defender Exploit Guard","ASR: Block persistence through WMI event subscription",MpPreferenceAsr,e6db77e5-3df2-4cf1-b95a-636979351e5b,,,,,,0,1,=,Medium
1947,"Microsoft Defender Exploit Guard","ASR: Block persistence through WMI event subscription (Intune)",Registry,e6db77e5-3df2-4cf1-b95a-636979351e5b,"HKLM:\Software\Policies\Microsoft\Windows Defender\Policy Manager",ASRRules,,,,0,1,=,Medium
1931,"Microsoft Defender Exploit Guard","ASR: Block abuse of exploited vulnerable signed drivers (Policy)",Registry,,"HKLM:\Software\Policies\Microsoft\Windows Defender\Windows Defender Exploit Guard\ASR\rules",56a863a9-875e-4185-98a7-b882c64b5ce5,,,,0,1,=,Medium
1932,"Microsoft Defender Exploit Guard","ASR: Block abuse of exploited vulnerable signed drivers",MpPreferenceAsr,56a863a9-875e-4185-98a7-b882c64b5ce5,,,,,,0,1,=,Medium
1948,"Microsoft Defender Exploit Guard","ASR: Block abuse of exploited vulnerable signed drivers (Intune)",Registry,56a863a9-875e-4185-98a7-b882c64b5ce5,"HKLM:\Software\Policies\Microsoft\Windows Defender\Policy Manager",ASRRules,,,,0,1,=,Medium
1966,"Microsoft Defender Exploit Guard","ASR: Exclude files and paths from Attack Surface Reduction Rules (Policy)",Registry,,"HKLM:\Software\Policies\Microsoft\Windows Defender\Windows Defender Exploit Guard\ASR",ExploitGuard_ASR_ASROnlyExclusions,,,,,,=,Medium
1967,"Microsoft Defender Exploit Guard","ASR: List of excluded files and paths from Attack Surface Reduction Rules",MpPreferenceExclusion,AttackSurfaceReductionOnlyExclusions,,,,,,,,=,Medium
1967,"Microsoft Defender Exploit Guard","ASR: Exclude files and paths from Attack Surface Reduction Rules",MpPreferenceExclusion,AttackSurfaceReductionOnlyExclusions,,,,,,,,=,Medium
1968,"Microsoft Defender Exploit Guard","ASR: Exclude files and paths from Attack Surface Reduction Rules (Intune)",Registry,,"HKLM:\Software\Policies\Microsoft\Windows Defender\Policy Manager",ASROnlyExclusions,,,,,,=,Medium
1965,"Microsoft Defender Exploit Guard","Network Protection: Prevent users and apps from accessing dangerous websites",Registry,,"HKLM:\SOFTWARE\Policies\Microsoft\Windows Defender\Windows Defender Exploit Guard\Network Protection",EnableNetworkProtection,,,,,1,=,Medium
1980,"Microsoft Defender Application Guard","Support for Microsoft Defender Application Guard",WindowsOptionalFeature,Windows-Defender-ApplicationGuard,,,,,,Disabled,Enabled,=,Medium
1981,"Microsoft Defender Application Guard","Turn on Microsoft Defender Application Guard in Managed Mode",Registry,,HKLM:\SOFTWARE\Policies\Microsoft\AppHVSI,AllowAppHVSI_ProviderSet,,,,,3,=,Medium
Expand Down
Loading

0 comments on commit dd76b5a

Please sign in to comment.