r/DefenderATP

What are free alternatives to applocker for windows 11 home

I heard that applocker can be configured to have a system wide whitelist for program and file permissions, something that can stop malware from running even if it gets on system if configured correctly. However, it is only on windows Enterprise editions. Threatlocker is the closest option I could find to replicate applocker. Yet, it is only available for businesses.

Are there any free programs/windows components which can provide similar functionality and work on windows 11 home?

reddit.com
u/EggsAreNotTrees — 1 day ago
▲ 10 r/DefenderATP+1 crossposts

Defender Scans Failing - Anyone Else?

We're using Defender for Endpoint throughout our environment. Beginning this morning, quick or full scans are failing, and will occasionally fail to the point where the Defender service needs to be restarted.

We came across this while responding to a separate infection - I chalked it up to Defender being borked due to the infection but then I was able to recreate the issue on other devices simply by initiating a Quick Scan.

Before I declare this a 5 alarm fire, anyone else having this issue?

AMEngineVersion AMProductVersion AntivirusSignatureVersion AntispywareSignatureVersion

--------------- ---------------- ------------------------- ---------------------------

1.1.26070.7 4.18.26070.9 1.457.219.0 1.457.219.0

reddit.com
u/Hazy_Arc — 2 days ago

Device Network Events

My understanding is that we have Sentinel integrated with Defender for XDR in the portal and defender info is ingested. However some tables like Device Network Events are empty. Microsoft documentation points me to the connector page but that doesn't show Defender for XDR (but it does seem to be ingesting the events). I'll have another look when I'm back in the office tomorrow, but if it's something easy I'm overlooking, I would be grateful

reddit.com
u/DaithiG — 4 days ago

Is blocking list of urls/domains with Defender Indicators a viable solution until GSA/Zscaler implementation?

There is an urgent need to block roughly 9000 domains/urls from all of the company workstations. Quite a lot, but from initial analysis only ~10% actually detected in environment over last 6 months. The request from business higher up still stands, block all provided domains/url and provide evidence of the block list containing them.

In past there were concerns about using large number of Defender Indicators to block, is that still the case? Any caveats or warnings that other want to share before we proceed?

A proper GSA/Zscaler solution is 6-9 months out, but the block must happen yesterday...

reddit.com
u/jM2me — 6 days ago

Qustion about best practices for Defender for O365

Hello, I am a student learning about microsoft security. I have tested built-in policies like anti -phising, anti-spam., etc. Is there any other best practices for defender for o365. I wanna know more about it because I need to present to my teacher next week.

reddit.com
u/Yuu_ll — 8 days ago

Defender Antivirus turned off notification on managed devices

I'm having an issue here with Microsoft Defender for Endpoint. I'm getting popup notifications that virus protection is turned off, yet Real time protection, cloud-delivered protection, tamper protection etc are all turned on and managed by policy. This is happening on several Intune managed devices being marked non-compliant. Policies haven't changed. What could be the issue?

reddit.com
u/mR_R3boot — 8 days ago

Threat hunting on Microsoft Defender XDR mapped to MITRE ATT&CK

I put together a collection of practical threat hunting and detection queries for:

  • Microsoft Defender XDR (KQL)

The queries focus on real-world behaviors: LOLBins, suspicious process chains, persistence, credential access, lateral movement, C2 patterns, and some APT-style activity. Most are mapped to MITRE ATT&CK techniques and include short comments + tunable parameters.

Actively adding queries based on recent threat intel and campaigns. Feedback, suggestions for missing coverage, or contributions are very welcome.

Repo: Threat-Hunting/KQL at main · a2awais/Threat-Hunting

reddit.com
u/iawais — 9 days ago

Duplicate Alerts from Custom Detections in Advanced Hunting

Hi all,

Was hoping someone could help me figure out why I keep getting duplicate alerts for my custom detections.

When I create them and run them, I get 1 alert. However, when they auto-run, they will send me 1 of the same alert, every hour, for the next few hours. Im assuming its something to do with the Frequency + Lookback.

For example, I look for something in the table EmailEvents. Then, it triggers at 10am - 1 alert - Perfect.

However, that same alert will trigger again at 11am, 12pm, and 1pm.

I have been doing 1 hour frequency and 4 hour lookback. Am i supposed to make them equal? How do I make the alerts not duplicate the same alert every hour?

reddit.com
u/Cant_Think_Name12 — 8 days ago

False Positives in DisruptionAndResponseEvents schema?

Hi Guys,

Last week we received multiple alerts (>100 alerts) with "Lateral movement using remote logon by contained user blocked"

I already checked several times for different logontypes, SMB, RDP, RPC, etc. events and found no suspicious behavior on our environment.

Then, apparently just within the same day I discovered that there seem to be a new schema under ATH "DisruptionAndResponseEvents". The alerts I received was the entry under this schema for the past 30days.

Is this most likely a False Positive and have you guys experienced this on your end too?

Would appreciate any insights on this guys.

reddit.com
u/LadyJohn21 — 9 days ago

Defender for Identity v3 requires MDE onboarding?

One of the new requirements for v3 release is:

>Has Defender for Endpoint deployed on the server. The Microsoft Defender Antivirus component can be in either active or passive mode. Defender for Endpoint must be onboarded on the server where the sensor runs; endpoint-only deployment isn't sufficient.

We use CrowdStrike EDR on the servers, and stack that with the Windows Server built-in Defender in active state, this includes Defender for Identity v2 agents. This is our stacked approach, while ensuring that the server is not exposed to any Defender cloud management plane, etc.

Was looking to upgrade to v3, and it seems that the new requirement is to onboard the server to Defender for Endpoint.

When it is on-boarded, what does that mean for the server? Is it now running Defender for Endpoint EDR?

reddit.com
u/-c3rberus- — 10 days ago

EDR CPU utilization issues

Over the past few weeks I’ve been receiving reports of horrible computer hang ups and in a lot of cases I’m seeing the MSSense service change from delayed start to automatic right before this occurs - it’s sometimes followed up by a CoPilot or Teams (or both update) and then the service switches back from automatic to delayed. The EDR process is one of the top hitters during this period along with SVChost and our RMM tool.

I’m curious if anyone has seen this or knows what is happening when this occurs.

I’ve been reading up on EDR exclusions and will look into excluding the RMM tool but the CoPilot update is not delivered by it and seems to be a trigger in some of these cases.

reddit.com
u/autojack — 12 days ago
▲ 10 r/DefenderATP+1 crossposts

No Internet, How to Deploy Security Intelligence definitions for MDE offline

I work in a Financial Institution where we have a section of our internal network endpoints not connected to the internet. We are deploying Microsoft MDE as our Antivirus and I have been tasked to make sure these Endpoints that do not have internet access are also MDE onboarded. I need someone to give me ideas as to how to carry out this task. 1. Can I install a server onprem that has internet connection, download the virus definitions and pushed them to these endpoints, is it feasible and how can I carry that out. I am currently out of ideas I need help.

reddit.com
u/Worldly-Secretary837 — 13 days ago

Help Building Windows Defender Offline CD With Old OS and RAID

I want to scan an old Windows 8.1 system for viruses (it has more than one). I downloaded the Windows Defender X64 offline scanner and installed as an ISO. on a clean Windows 11 computer.

Here is where it gets complicated. The Dell storage system on the computer is a PERC H310. Dell never supported Windows 10 on this controller. But the controller is a remarketed LSI 9240, and LSI still distributes the latest driver for that controller, which is a Windows 10 X64 driver. I patched the Windows ISO with the LSI 9240 X64 drivers for Windows 10 and then burned a CD.

Unfortunately, the Windows Defender boot disk bombs with the blue screen of death, and predictably that is while loading the megaraid driver. At this point do I have any options for running Windows Defender Offline?

I looked for other offline virus scanners, and almost all of the well-known ones appear to have disappeared. Kaspersky refuses to talk to US customers. ESET apparently does not give it away for free. Avast wants you to install their anti-virus software first. Are there any good offline rootkit scanners that would do a good job on an older Windows 8.1 system?

reddit.com
u/smorgasmic — 13 days ago