Windows Defender attack surface reduction and exploit protection features

To support me, you can subscribe to the channel, share and like the videos, disable your ad blocker or make a donation. Thank you!


A video on Windows Defender’s attack surface reduction and Exploit protection features

# List of rules and documentation on reducing the attack surface

Exploit protection documentation

Powershell code for attack surface reduction and and Exploit protection for Windows Defender

#Enable all attack surface reduction rules (list of rules).
$rules = @("be9ba2d9-53ea-4cdc-84e5-9B1eeee46550"
Add-MpPreference -AttackSurfaceReductionRules_Ids $rules -AttackSurfaceReductionRules_Actions (0..($rules.Count -1) | % {"enabled"})
Add-MpPreference -AttackSurfaceReductionRules_Ids $rules -AttackSurfaceReductionRules_Actions (0..($rules.Count -1) | % {"disabled"})
#Add an exclusion for attack surface reduction
Add-MpPreference -AttackSurfaceReductionOnlyExclusions "c:\vm"
#Display attack surface reduction parameters (1: Enabled, 0: Disabled)
$FormatEnumerationLimit = 20
Get-MpPreference | fl attack*
#Display list of rules
Get-MpPreference | Select-Object -ExpandProperty AttackSurfaceReductionRules_Ids
# Powershell command to test the rule Block process creation from PSExec and WMI defender commands ASR advanced options
Invoke-CimMethod -ClassName Win32_Process -MethodName Create -Arguments @{CommandLine='Notepad.exe'}

Video : Windows Defender attack surface reduction and exploit protection features

Related links