Microsoft Defender Antivirus Security Technical Implementation Guide
Rules, Groups, and Values defined within the XCCDF Benchmark
-
Microsoft Defender AV must be configured to block Office applications from injecting into other processes.
<VulnDiscussion>Office apps, such as Word, Excel, or PowerPoint, will not be able to inject code into other processes. This is typically used...Rule Medium Severity -
SRG-APP-000210
<GroupDescription></GroupDescription>Group -
Microsoft Defender AV must be configured to impede JavaScript and VBScript to launch executables.
<VulnDiscussion>JavaScript and VBScript scripts can be used by malware to launch other malicious apps. This rule prevents these scripts from ...Rule Medium Severity -
SRG-APP-000210
<GroupDescription></GroupDescription>Group -
Microsoft Defender AV must be configured to disable local setting override for reporting to Microsoft MAPS.
<VulnDiscussion>This policy setting configures a local override for the configuration to join Microsoft MAPS. This setting can only be set by...Rule Medium Severity -
SRG-APP-000278
<GroupDescription></GroupDescription>Group -
SRG-APP-000279
<GroupDescription></GroupDescription>Group -
Microsoft Defender AV must be configured to not allow override of monitoring for incoming and outgoing file activity.
<VulnDiscussion>This policy setting configures a local override for the configuration of monitoring for incoming and outgoing file activity. ...Rule Medium Severity -
SRG-APP-000209
<GroupDescription></GroupDescription>Group -
Microsoft Defender AV must be configured to not allow override of scanning for downloaded files and attachments.
<VulnDiscussion>This policy setting configures a local override for the configuration of scanning for all downloaded files and attachments. T...Rule Medium Severity -
SRG-APP-000210
<GroupDescription></GroupDescription>Group -
Microsoft Defender AV must be configured to automatically take action on all detected tasks.
<VulnDiscussion>This policy setting allows Microsoft Defender configuration to automatically take action on all detected threats. The action ...Rule Medium Severity -
SRG-APP-000278
<GroupDescription></GroupDescription>Group -
Microsoft Defender AV must be configured to run and scan for malware and other potentially unwanted software.
<VulnDiscussion>This policy setting turns off Microsoft Defender Antivirus. If this policy setting is enabled, Microsoft Defender Antivirus d...Rule High Severity -
SRG-APP-000278
<GroupDescription></GroupDescription>Group -
Microsoft Defender AV must be configured to not exclude files for scanning.
<VulnDiscussion>This policy setting allows disabling of scheduled and real-time scanning for files under the paths specified or for the fully...Rule Medium Severity -
SRG-APP-000278
<GroupDescription></GroupDescription>Group -
Microsoft Defender AV must be configured to not exclude files opened by specified processes.
<VulnDiscussion>This policy setting allows the disabling of scheduled and real-time scanning for any file opened by any of the specified proc...Rule Medium Severity -
SRG-APP-000278
<GroupDescription></GroupDescription>Group -
Microsoft Defender AV must be configured to enable the Automatic Exclusions feature.
<VulnDiscussion>This setting allows an administrator to specify if Automatic Exclusions feature for Server SKUs should be turned off.</Vul...Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.