22.20 (L1) Ensure 'ASR: Block untrusted and unsigned processes that run from USB' is set to 'Block'

Information

With this rule, admins can prevent unsigned or untrusted executable files from running from USB removable drives, including SD cards. Blocked file types include executable files (such as .exe, .dll, or .scr)

The recommended state for this setting is: Block

Attack surface reduction helps prevent actions and apps that are typically used by exploit-seeking malware to infect machines.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Block

Defender\Block untrusted and unsigned processes that run from USB

Impact:

Files copied from the USB to the disk drive will be blocked by this rule if and when it's about to be executed on the disk drive.

See Also

https://workbench.cisecurity.org/benchmarks/21719

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-16, CSCv7|8.3

Plugin: Windows

Control ID: 09451a04fef282e62a4bdacef3a9ea8542d9b36647b77a5bc801645041bf003a