Inspecting Microsoft Defender Attack Surface Reduction Rules

What I will be covering in this article 👇🏽 Not a How, but more of a WhyProactive Prevention Vs. Reactive DetectionThe Ever-Expanding Attack SurfaceWhy Does Attack Surface Management Matter? - Painting the Picture With An ExampleA Good Rollout RoadmapPolicy Exceptions - Experience From the FieldPlanning the DeploymentLet's Categorize the RulesUnderstanding the ASR Rule ModesIf You … Continue reading Inspecting Microsoft Defender Attack Surface Reduction Rules

Microsoft Defender for Endpoint – Passive Mode

Passive mode and EDR in block mode. It's fair to assume that if Defender is not the "Active" or the "Primary" AV on the computer, then that will be running in Passive mode. However, in the Defender world, it is one of the states where you can leave Defender running. However, that might not be … Continue reading Microsoft Defender for Endpoint – Passive Mode