22.22 (L1) Ensure 'ASR: Use advanced protection against ransomware' is set to 'Audit' or higher

Information

This rule provides an extra layer of protection against ransomware. It uses both client and cloud heuristics to determine whether a file resembles ransomware. This rule doesn't block files that have one or more of the following characteristics:

The file has already been found to be unharmful in the Microsoft cloud.The file is a valid signed file.The file is prevalent enough to not be considered as ransomware.The rule tends to err on the side of caution to prevent ransomware.

The recommended state for this setting is: Audit Configuring this setting to Block also conforms to the benchmark.

Note: Cloud-delivered protection must be enabled to use this rule.

This ASR rule is can help an organization enhance it's protection against ransomware by using both cloud and local heuristics.

Note: Cloud-delivered protection must be enabled to use this rule.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Audit or Block

Defender\Use advanced protection against ransomware

Impact:

Implementing this control could impact certain workflows, making it unsuitable for universal enforcement across the organization without first adding exceptions. Therefore, it is recommended to start in Audit mode and then move to Block mode after creating exceptions. This approach allows for a better understanding of the environment through extensive monitoring of the rule.

See Also

https://workbench.cisecurity.org/benchmarks/21767

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-16, CSCv7|8.3

Plugin: Windows

Control ID: 2b01d8787620b7c078a953664b64e7a9d60b595a3416aa15bee8ab6d369452e6