Skip to content

Microsoft Defender Antivirus Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-APP-000210

    <GroupDescription></GroupDescription>
    Group
  • Microsoft Defender AV must be configured block Office applications from creating child processes.

    &lt;VulnDiscussion&gt;Office apps, such as Word or Excel, will not be allowed to create child processes. This is a typical malware behavior, especi...
    Rule Medium Severity
  • SRG-APP-000210

    <GroupDescription></GroupDescription>
    Group
  • Microsoft Defender AV must be configured block Office applications from creating executable content.

    &lt;VulnDiscussion&gt;This rule targets typical behaviors used by suspicious and malicious add-ons and scripts (extensions) that create or launch e...
    Rule Medium Severity
  • Microsoft Defender AV must be configured to block execution of potentially obfuscated scripts.

    &lt;VulnDiscussion&gt;Malware and other threats can attempt to obfuscate or hide their malicious code in some script files. This rule prevents scri...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules