How to start working with Attack Surface Reduction rules like a boss

  Рет қаралды 4,880

MSEndpointMgr - Jungling the Cloud

MSEndpointMgr - Jungling the Cloud

Күн бұрын

Пікірлер: 14
@simonkeen9776
@simonkeen9776 2 жыл бұрын
Thanks to Kent for this presentation
@MSEndpointMgr
@MSEndpointMgr 2 жыл бұрын
Thanks for your comment Simon! Glad you liked it
@aneeshnicola9981
@aneeshnicola9981 Жыл бұрын
​@MSEndpointMgr Do we need to enable cloud block level as high to receive the toast notifications on the enduser device level for asr warn mode .Is this any prerequisiste ? Looking for assistance pls since im not receiving the notifications which allow me to bypass despite configuring warn mode
@karthikeyanv3400
@karthikeyanv3400 Жыл бұрын
Thank you both, excellent walkthrough.
@MSEndpointMgr
@MSEndpointMgr Жыл бұрын
You are most welcome!
@Rahgozar633
@Rahgozar633 Жыл бұрын
Hi, thank you for the informative video. I have a question that wasn't answered by Microsoft either. Sometimes, certain executable files that attempt to access LSASS are blocked on some devices, even though these files can run without issues on other devices. What could be the reason behind this if the file isn't malicious?
@MSEndpointMgr
@MSEndpointMgr Жыл бұрын
Hi Milad That is a very good question, that I have asked myself. Programs with access to LSASS should be considered as threats. I am no security expert, but LSASS is there to help windows with credentials and not 3rd party apps. If the program gets access and dump the LSASS credentials an attacker would easily be able to move laterally across the network with tools like psexec og WMI. So blocking the access to LSASS would be my default until I see stuff break because of this.
@Rahgozar633
@Rahgozar633 Жыл бұрын
@@MSEndpointMgr Hi, thank you for your feedback. The problem is that certain files or applications require access to LSASS, and it is not clear why these specific files are able to access LSASS on one device without raising suspicion from Microsoft. However, the same file or application may be blocked on another device, and it is unclear what has caused this. In such cases, it is uncertain whether the file should be excluded from this ASR rule or not.
@MSEndpointMgr
@MSEndpointMgr Жыл бұрын
@@Rahgozar633 I see your point. I guess the only way to find out will be to ask the vendor of the software that tries to access LSASS if this really is needed
@aneeshnicola9981
@aneeshnicola9981 Жыл бұрын
@MSEndpointMgr Do we need to enable cloud block level as high to receive the toast notifications on the enduser device level for asr warn mode .Is this any prerequisiste ? Looking for assistance pls since im not receiving the notifications which allow me to bypass despite configuring warn mode
@MSEndpointMgr
@MSEndpointMgr Жыл бұрын
Good question. Yes you need cloud block level set to high otherwise you will be shown nothing. Also your rules might need to be in block mode, but some will also show a toast notification even in audit. You can see the full picture here: learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/attack-surface-reduction-rules-reference?view=o365-worldwide#per-asr-rule-alert-and-notification-details
@KA-NV
@KA-NV Жыл бұрын
@@MSEndpointMgr could provide were to find the option to enable cloud block level? Thanks
@edemfromeden5432
@edemfromeden5432 2 жыл бұрын
It always amazes me how much MSFT is NOT aligned in regards to best practices. The speaker advice goes like this "don't play around with ring1, ring2 deploy to all". At the same time offical ASR docs state the opposite O_o.
@MSEndpointMgr
@MSEndpointMgr 2 жыл бұрын
It all depends on the scenario. I know such a borring answer. But a ring rollout method is always a good thing to prevent large scale bummers.
The why and how of KQL with guest Rod Trent
1:25:53
MSEndpointMgr - Jungling the Cloud
Рет қаралды 667
Attack Surface Reduction | Virtual Ninja Training with Heike Ritter
39:34
Microsoft Security Community
Рет қаралды 9 М.
Cheerleader Transformation That Left Everyone Speechless! #shorts
00:27
Fabiosa Best Lifehacks
Рет қаралды 16 МЛН
Attack Surface Reduction implementation report
14:05
Jackson Felden - Cloud and Security
Рет қаралды 1,8 М.
Microsoft Intune From Zero to Hero
39:08
Andy Malone MVP
Рет қаралды 289 М.
Deploy Attack Surface Reduction Rules from Microsoft Intune
23:58
Concepts Work
Рет қаралды 9 М.
Learn Microsoft Active Directory (ADDS) in 30mins
36:26
Andy Malone MVP
Рет қаралды 1 МЛН
What's new in Microsoft Intune (2306 & 2307)
59:13
MSEndpointMgr - Jungling the Cloud
Рет қаралды 1,3 М.
How TCP really works // Three-way handshake // TCP/IP Deep Dive
1:01:10
Attack surface reduction in Microsoft Defender for Endpoint
6:36
Microsoft Security
Рет қаралды 20 М.