22.12 (L1) Ensure 'ASR: Block executable files from running unless they meet a prevalence, age, or trusted list criterion' is set to 'Audit' or higher

Information

This rule blocks executable files, such as .exe, .dll, or .scr, from launching. Thus, launching untrusted or unknown executable files can be risky, as it might not be initially clear if the files are malicious.

The recommended state for this setting is: Audit Configuring this setting to Block also conforms to the benchmark.

Note: Cloud-delivered protection must be enabled to use this rule.

Organizations may find implementing Block to be too strict, however in Audit mode there is still valuable information that can be logged for threat hunters to sift through and analyze.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Audit or Block

Defender\Block executable files from running unless they meet a prevalence, age, or trusted list criterion

Impact:

In order to parse audit logs effectively an organization may need to implement a SIEM solution.

See Also

https://workbench.cisecurity.org/benchmarks/21767

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-16, CSCv7|8.3

Plugin: Windows

Control ID: 4a582a6cb3832938026661726cc5da5c5c5d2c35c3e162882707c81298e4d9ba