Microsoft Defender ATP Training Series Part 3: Attack Surface Reduction (ASR)

  Рет қаралды 4,548

Ambarish RH

Ambarish RH

Күн бұрын

Пікірлер: 26
@adeyemiakanfe7641
@adeyemiakanfe7641 3 жыл бұрын
Your video is superb.
@AmbarishRH
@AmbarishRH 3 жыл бұрын
Thanks a lot,glad you like it!
@SkilfulPranks
@SkilfulPranks 4 жыл бұрын
Great and good explanation.
@AmbarishRH
@AmbarishRH 4 жыл бұрын
Glad you liked it!
@ayomidetaylor5675
@ayomidetaylor5675 3 жыл бұрын
Solid series. Great!
@AmbarishRH
@AmbarishRH 3 жыл бұрын
Thank you!
@alessandrosantos7582
@alessandrosantos7582 4 жыл бұрын
Great ! Could you create a video with Web Content, the setup please.
@AmbarishRH
@AmbarishRH 4 жыл бұрын
Hi Alessandro, hope this is about the web content filtering via defender. If so, its on my list. Thanks
@alessandrosantos7582
@alessandrosantos7582 4 жыл бұрын
@@AmbarishRH Amazing !
@naveeenkumarpothuganti1482
@naveeenkumarpothuganti1482 2 жыл бұрын
Super sir
@loveadrisha
@loveadrisha 4 жыл бұрын
Very nice presentation👌
@AmbarishRH
@AmbarishRH 4 жыл бұрын
Thank you! Cheers!
@vipuldabhi6971
@vipuldabhi6971 2 жыл бұрын
Need to know the best practice to implement ASR.. this more on post implementation aspects of ASR
@AmbarishRH
@AmbarishRH 2 жыл бұрын
I would suggest to look at the secure score and recommendations on defender portal which will show you the best ASR policoes to deploy based on criticality and also it shows you impacts on user per rule
@vipuldabhi6971
@vipuldabhi6971 2 жыл бұрын
Also need to know how to check or confirm if a device is enabled with ASR,
@AmbarishRH
@AmbarishRH 2 жыл бұрын
You can find this from defender portal-reports- under Endpoints- Attack Surface Reduction Rules
@vaibhavchaturvedi5174
@vaibhavchaturvedi5174 4 жыл бұрын
Hi Ambarish, please make a video on Azure security center and Azure ATP.
@AmbarishRH
@AmbarishRH 4 жыл бұрын
Hi Vaibhav, thanks for the feedback. I have these scheduled in the coming sessions. However, feel free to reach out if you need to know anything in specific
@6123arvind
@6123arvind 4 жыл бұрын
where are other parts of atp like EDR , automatic invest. and remediation ... thanks for first 3 parts
@AmbarishRH
@AmbarishRH 4 жыл бұрын
Each one of those features coming soon in the next videos
@avinashsudulagunta9470
@avinashsudulagunta9470 3 жыл бұрын
Hi Sir , How we get to know whether ASR Rules affected by VBA Automation or not., and is there any way we to make sure that VBA cannot affect the ASR rules
@AmbarishRH
@AmbarishRH 3 жыл бұрын
Hi Avinash, You could use the troubleshooting methods listed docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/troubleshoot-asr-rules?view=o365-worldwide In your case, you could run advanced hunting queries from security.microsoft.com/advanced-hunting and use the query as below example DeviceEvents | where ActionType startswith 'Asr' | where InitiatingProcessFolderPath contains "VBAscriptname" You can also use the exclusions in ASR if you want something to be excluded from ASR rules. docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/attack-surface-reduction-faq?view=o365-worldwide
@aneeshnicola9981
@aneeshnicola9981 2 жыл бұрын
How can we test using the ASR tool?
@AmbarishRH
@AmbarishRH 2 жыл бұрын
ideal way is to setup test/pilot drvice and apply rules one by one, vareify the impact using ASR hunting scripts or from the reports section on security.micrososft.com- ASR reprts abd based on requirements add exceptions, then test and roll out to prpduction
@omerkhan4049
@omerkhan4049 4 жыл бұрын
how can i export AV definition and out date Definition/signature
@AmbarishRH
@AmbarishRH 4 жыл бұрын
Hope you are referring to www.microsoft.com/en-us/wdsi/defenderupdates
Attack Surface Reduction Rules | Deployment Methods and Modes
14:41
Concepts Work
Рет қаралды 3,4 М.
Try this prank with your friends 😂 @karina-kola
00:18
Andrey Grechka
Рет қаралды 9 МЛН
Attack surface reduction in Microsoft Defender for Endpoint
6:36
Microsoft Security
Рет қаралды 19 М.
How to start working with Attack Surface Reduction rules like a boss
33:01
MSEndpointMgr - Jungling the Cloud
Рет қаралды 4,8 М.
Block Cred Dumps using Attack Surface Reduction Rules in Windows
6:14
Deploy Attack Surface Reduction Rules from Microsoft Intune
23:58
Concepts Work
Рет қаралды 9 М.
Configure Attack Surface Reduction Rules | Group Policy
11:56
Concepts Work
Рет қаралды 3,3 М.
Microsoft Defender Training Series Part4 Web Content Filtering
11:51