Protections in Defender for Endpoint that close off behaviour attackers like to abuse. Chief among them are ASR rules, which on Windows can stop Office programs spawning child processes or obfuscated scripts from running.
Also called ASR.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Attack surface reduction in context, with comparison tables and the common traps.
Terms in this definition
- LIKE
Compares strings with a pattern that can contain the % and _ wildcards. Because it only understands character patterns, searching big volumes of text this way is much slower than using full-text search.
- Stop sequence
One of up to four strings that make the model halt generation; the sequence itself is not included in the output.
Related terms
- Controlled configuration
In preview, this builds on tamper protection so Antivirus and ASR settings coming from Intune override anything set locally, by Configuration Manager or by Group Policy. You turn it on in the Antivirus profile of the Windows Security experience.
- Defender for Endpoint Plan 1
Bundled with Microsoft 365 E3, the entry-level Defender for Endpoint tier offers protection features (next-generation antivirus and attack surface reduction), central management and manual response, while EDR, advanced hunting and automated investigation are all missing from it.
- Endpoint security policies
Settings for things like the firewall, EDR, antivirus and ASR rules, defined in either Intune or the Defender portal. Defender for Endpoint security settings management is what delivers them to machines.
- LSASS
The Windows process responsible for authenticating sign-ins, which keeps credentials in memory and is therefore a favourite target for credential theft. An attack surface reduction rule guards it, though that rule adds nothing once LSA protection is enabled.
- Network protection
Brings SmartScreen protection to every process on a device, so Defender for Endpoint can stop outbound connections to IP or URL indicators and to domains with a poor reputation. It is part of attack surface reduction and acts once the TCP handshake has finished.
- Standard protection rules
Attack surface reduction rules Microsoft suggests turning on in block mode after only light testing, for example stopping credential theft from LSASS or misuse of vulnerable signed drivers.