{"id":6355,"date":"2022-11-22T22:02:59","date_gmt":"2022-11-22T22:02:59","guid":{"rendered":"https:\/\/pariswells.com\/blog\/?p=6355"},"modified":"2025-10-16T02:11:45","modified_gmt":"2025-10-16T02:11:45","slug":"audit-mode-for-attack-surface-reduction-rules-in-intune-defender","status":"publish","type":"post","link":"https:\/\/pariswells.com\/blog\/research\/audit-mode-for-attack-surface-reduction-rules-in-intune-defender","title":{"rendered":"Audit Mode for Attack surface reduction rules in Intune \\ Defender"},"content":{"rendered":"\n<p>Recently I enabled Audit mode on some Attack surface reduction rules for Essential 8<\/p>\n\n\n\n<p>After a weeks worth of Auditing , I needed to track down what if anything had been audited. Per Microsoft blog :&nbsp;<a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2019\/02\/22\/recommendations-for-deploying-the-latest-attack-surface-reduction-rules-for-maximum-impact\/\">Recommendations for deploying the latest Attack surface reduction rules for maximum impact &#8211; Microsoft Security Blog<\/a><\/p>\n\n\n\n<p>Audit mode will identify exploitable behavior use but will not block the behavior. With audit, if you have a line of business application utilizing a behavior that is exploitable, the invoking application can be identified, and an exclusion added.<\/p>\n\n\n\n<p>You can review the audited events with&nbsp;<a class=\"\" href=\"https:\/\/docs.microsoft.com\/en-us\/windows\/security\/threat-protection\/windows-defender-atp\/investigate-alerts-windows-defender-advanced-threat-protection\">Advanced hunting and Alert investigation<\/a>&nbsp;in Windows Defender Security Center<\/p>\n\n\n\n<p>Hunting requires building queries , however there is a pre-programmed report in&nbsp;<a href=\"https:\/\/security.microsoft.com\/\">https:\/\/security.microsoft.com\/<\/a>&nbsp;that will do this already ( Blocked and Or Audited )&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2022\/11\/image-4.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"388\" src=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2022\/11\/image-4-1024x388.png\" alt=\"\" class=\"wp-image-9297 img-responsive\" srcset=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2022\/11\/image-4-1024x388.png 1024w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2022\/11\/image-4-300x114.png 300w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2022\/11\/image-4-768x291.png 768w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2022\/11\/image-4-1536x581.png 1536w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2022\/11\/image-4.png 1791w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n\n\n\n<p>How to Audit Controller Folder Access with Advanced Hunting<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code class=\"\">DeviceEvents\n| where ActionType in ('ControlledFolderAccessViolationAudited','ControlledFolderAccessViolationBlocked')<\/code><\/pre>\n\n\n\n<p>How to Audit PUA Events<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code class=\"\">DeviceEvents\n| where ActionType == \"AntivirusDetection\"<\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>Recently I enabled Audit mode on some Attack surface reduction rules for Essential 8 After a weeks worth of Auditing , I needed to track down what [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[4090,2548,4089,4091,2509],"class_list":["post-6355","post","type-post","status-publish","format-standard","hentry","category-research","tag-attack-surface-reduction-rules","tag-audit","tag-audit-mode","tag-defender","tag-logs"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/6355","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/comments?post=6355"}],"version-history":[{"count":2,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/6355\/revisions"}],"predecessor-version":[{"id":9299,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/6355\/revisions\/9299"}],"wp:attachment":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/media?parent=6355"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/categories?post=6355"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/tags?post=6355"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}