Skip to content

I - Mission Critical Classified

Rules and Groups employed by this XCCDF Profile

  • SRG-APP-000210

    Group
  • Microsoft Defender AV must be configured block Office applications from creating child processes.

    Office apps, such as Word or Excel, will not be allowed to create child processes. This is a typical malware behavior, especially for macro-based attacks that attempt to use Office apps to launch o...
    Rule Medium Severity
  • SRG-APP-000210

    Group
  • Microsoft Defender AV must be configured block Office applications from creating executable content.

    This rule targets typical behaviors used by suspicious and malicious add-ons and scripts (extensions) that create or launch executable files. This is a typical malware technique. Extensions will be...
    Rule Medium Severity
  • SRG-APP-000210

    Group
  • Microsoft Defender AV must be configured to block Office applications from injecting into other processes.

    Office apps, such as Word, Excel, or PowerPoint, will not be able to inject code into other processes. This is typically used by malware to run malicious code in an attempt to hide the activity fro...
    Rule Medium Severity
  • SRG-APP-000210

    Group
  • Microsoft Defender AV must be configured to impede JavaScript and VBScript to launch executables.

    JavaScript and VBScript scripts can be used by malware to launch other malicious apps. This rule prevents these scripts from being allowed to launch apps, thus preventing malicious use of the scrip...
    Rule Medium Severity
  • SRG-APP-000210

    Group
  • Microsoft Defender AV must be configured to block execution of potentially obfuscated scripts.

    Malware and other threats can attempt to obfuscate or hide their malicious code in some script files. This rule prevents scripts that appear to be obfuscated from running. It uses the AntiMalwareSc...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules