Information
This rule blocks executable files, such as .exe, .dll, or .scr, from launching. Thus, launching untrusted or unknown executable files can be risky, as it might not be initially clear if the files are malicious.
The recommended state for this setting is: Audit Configuring this setting to Block also conforms to the benchmark.
Note: Cloud-delivered protection must be enabled to use this rule.
Organizations may find implementing Block to be too strict, however in Audit mode there is still valuable information that can be logged for threat hunters to sift through and analyze.
Solution
To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Audit or Block
Defender\Block executable files from running unless they meet a prevalence, age, or trusted list criterion
Impact:
In order to parse audit logs effectively an organization may need to implement a SIEM solution.