Explore tweets tagged as #ASRrules
@rodtrent
Speaker 25
3 years
Good Summary including links, KQL, PowerShell, etc. https://t.co/kODDn0t39J #KQL #PowerShell #ASRRules #MicrosoftDefender
0
11
33
@Sim0nEriksen
Simon Hartmann Eriksen
4 years
Great to see it is now available in the MEM Portal. #ASRrules
@Sim0nEriksen
Simon Hartmann Eriksen
4 years
Great that @DeviceDeploy and @MikeDanoski could confirm "Block abuse of exploited vulnerable signed drivers" will be part of GUI next week! 🙏 #MEMPowered #MSIntune
0
0
2
@I_Am_Jakoby
I am Jakoby
2 years
So i made an api endpoint, rendered a webpage, and even stored the asrRules in a DNS txt record for stealthy access. If you dont know what these are for or why they are cool watch for follow up posts Credit to: @BlackSnufkin42 for the base powershell script behind the
0
2
59
@kj_ninja25
Kijo Ninja
2 years
So exited to share my second query - ASR rules detection in Microsoft Sentinel GitHub, Hunting repo 🎉🎉🎉 ✅ KQL : https://t.co/M9bzCfPAN6 #MDE #EPP #EDR #ASR #ASRrules
0
7
41
@thebuj1
The Buj
15 years
Its party time this weekend #ASRrules http://twitpic.com/2d56iw
0
0
0
@kj_ninja25
Kijo Ninja
2 years
If you missed NinjaShow yesterday, you can watch it on YouTube!! I talked about #KQL, #AdvancedHunting in #MDE. Focused on #ASRrules and #WebProtection data visualization. https://t.co/85IcYAp4vR
0
7
17
@AlloJandro
Alejandro Alonso
14 years
Joder, no me imaginaba que hoy en día 6 euros en una discoteca dieran para semejante trozo que llevo encima #AsrRules
1
0
0
@kaidja
Kaido Järvemets
4 years
@DebugPrivilege Through Azure I'm using a custom DSC module but here is the simple version of it -
1
9
23
@jadeth_p
Jadeth
13 years
@GrnEyedCED I share the excitement! #Asrrules
1
0
0
@alut82
Aad Lutgert
1 year
Are you experiencing issues with your ASR rules? In one of my latest blogposts I explain how you can create ASR exclusion and deploy with Intune. #ASRrules #Exclusion #Microsoft #Intune #Windows Create an ASR Rules Exclusion -
0
1
4
@MariaJesus23_96
María Jesús Simón
11 years
Al fin juntos! 👌😊🎉 #ASRrules http://t.co/xji7UBZhAZ
0
0
0
@NathanMcNulty
Nathan McNulty
3 years
@neutroncore @DeviceDeploy Based on what I'm seeing, the settings do get tattooed When we set ASR rules from ConfigMgr, and it will set the registry values under \SOFTWARE\Policies\Microsoft\Windows Defender\Policy Manager ASRRules (String) Removing policy leaves the entry, so cleanup seems to be needed
1
0
1
@2code_monte
Rob Winter
2 years
0
0
0