| 18.9.47.9.2 (L1) Ensure 'Turn off real-time protection' is set to 'Disabled' | CIS Azure Compute Microsoft Windows Server 2022 v1.0.0 L1 DC | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 18.9.47.9.2 (L1) Ensure 'Turn off real-time protection' is set to 'Disabled' | CIS Azure Compute Microsoft Windows Server 2022 v1.0.0 L1 MS | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 18.9.47.9.2 (L1) Ensure 'Turn off real-time protection' is set to 'Disabled' | CIS Azure Compute Microsoft Windows Server 2019 v1.0.0 L1 DC | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 18.9.77.14 Ensure 'Turn off Windows Defender AntiVirus' is set to 'Disabled' | CIS Windows 7 Workstation Level 1 v3.2.0 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 18.9.77.14 Ensure 'Turn off Windows Defender AntiVirus' is set to 'Disabled' | CIS Microsoft Windows 8.1 v2.4.1 L1 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 18.10.43.10.2 (L1) Ensure 'Turn off real-time protection' is set to 'Disabled' | CIS Windows Server 2012 R2 DC L1 v3.0.0 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 18.10.43.10.2 (L1) Ensure 'Turn off real-time protection' is set to 'Disabled' | CIS Windows Server 2012 MS L1 v3.0.0 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 18.10.43.10.3 (L1) Ensure 'Turn off real-time protection' is set to 'Disabled' | CIS Microsoft Windows Server 2019 Stand-alone v3.0.0 L1 MS | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 18.10.43.10.3 (L1) Ensure 'Turn off real-time protection' is set to 'Disabled' | CIS Microsoft Windows 10 Enterprise v4.0.0 L1 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 18.10.43.10.3 (L1) Ensure 'Turn off real-time protection' is set to 'Disabled' | CIS Microsoft Windows 10 Enterprise v4.0.0 L1 BL | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 18.10.43.10.3 (L1) Ensure 'Turn off real-time protection' is set to 'Disabled' | CIS Microsoft Windows 10 Enterprise v4.0.0 L1 BL NG | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 18.10.43.10.3 (L1) Ensure 'Turn off real-time protection' is set to 'Disabled' | CIS Microsoft Windows 10 Enterprise v4.0.0 L1 NG | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 18.10.43.10.3 (L1) Ensure 'Turn off real-time protection' is set to 'Disabled' | CIS Microsoft Windows 10 Stand-alone v4.0.0 L1 BL NG | Windows | SYSTEM AND INFORMATION INTEGRITY |
| WNDF-AV-000001 - Microsoft Defender AV must be configured to block the Potentially Unwanted Application (PUA) feature. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| WNDF-AV-000007 - Microsoft Defender AV must be configured to enable the Automatic Exclusions feature. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| WNDF-AV-000008 - Microsoft Defender AV must be configured to disable local setting override for reporting to Microsoft MAPS. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000009 - Microsoft Defender AV must be configured to check in real time with MAPS before content is run or accessed. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| WNDF-AV-000010 - Microsoft Defender AV must join Microsoft MAPS. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000012 - Microsoft Defender AV must be configured for protocol recognition for network protection. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| WNDF-AV-000013 - Microsoft Defender AV must be configured to not allow local override of monitoring for file and program activity. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000014 - Microsoft Defender AV must be configured to not allow override of monitoring for incoming and outgoing file activity. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000015 - Microsoft Defender AV must be configured to not allow override of scanning for downloaded files and attachments. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000016 - Microsoft Defender AV must be configured to not allow override of behavior monitoring. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000018 - Microsoft Defender AV must monitor for incoming and outgoing files. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| WNDF-AV-000019 - Microsoft Defender AV must be configured to monitor for file and program activity. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| WNDF-AV-000020 - Microsoft Defender AV must be configured to scan all downloaded files and attachments. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000022 - Microsoft Defender AV must be configured to enable behavior monitoring. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000024 - Microsoft Defender AV must be configured to scan archive files. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| WNDF-AV-000025 - Microsoft Defender AV must be configured to scan removable drives. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | MAINTENANCE |
| WNDF-AV-000026 - Microsoft Defender AV must be configured to perform a weekly scheduled scan. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| WNDF-AV-000028 - Microsoft Defender AV spyware definition age must not exceed 7 days. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| WNDF-AV-000031 - Microsoft Defender AV must be configured for automatic remediation action to be taken for threat alert level Severe. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000038 - Microsoft Defender AV must be configured to block Win32 imports from macro code in Office. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000041 - Microsoft Defender AV must be configured for automatic remediation action to be taken for threat alert level Medium. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000042 - Microsoft Defender AV must be configured for automatic remediation action to be taken for threat alert level Low. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000044 - Microsoft Defender AV must block credential stealing from the Windows local security authority subsystem. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000045 - Microsoft Defender AV must block untrusted and unsigned processes that run from USB. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000046 - Microsoft Defender AV must use advanced protection against ransomware. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000047 - Microsoft Defender AV must audit process creations originating from PSExec and WMI commands. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000048 - Microsoft Defender AV must audit persistence through WMI event subscription. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000049 - Microsoft Defender AV must audit executable files from running unless they meet a prevalence, age, or trusted list criterion. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000052 - Microsoft Defender AV must configure local administrator merge behavior for lists. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000055 - Microsoft Defender AV must randomize scheduled task times. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| WNDF-AV-000056 - Microsoft Defender AV must hide the Family options area. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000057 - Microsoft Defender AV must enable the file hash computation feature. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000064 - Microsoft Defender AV must enable script scanning. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| WNDF-AV-000070 - Microsoft Defender AV must enable EDR in block mode. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000073 - Microsoft Defender AV must set cloud protection level to High. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000074 - Microsoft Defender AV must convert warn verdict to block. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000076 - Microsoft Defender AV must scan packed executables. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND INFORMATION INTEGRITY |