Skip to content
Threat Feed
low advisory

Monitoring Microsoft Defender Attack Surface Reduction Events

This brief details the ingestion and correlation of Microsoft Defender Attack Surface Reduction (ASR) events to identify policy bypasses, configuration tampering, and malicious execution attempts.

This brief focuses on the visibility into Microsoft Defender's Attack Surface Reduction (ASR) and Exploit Guard feature set. By ingesting and monitoring specific Windows Defender Operational log events, security operations teams can track security control performance, identify potential policy enforcement gaps, and detect adversary attempts to bypass system protections. The monitoring capability covers blocking events (Event IDs 1121, 1126, 1131, 1133), audit-only events (Event IDs 1122, 1125, 1132, 1134), user-initiated overrides (Event ID 1129), and registry-based configuration changes (Event ID 5007).

These telemetry sources are essential for establishing a baseline of authorized security operations. Sudden spikes in block events or unauthorized configuration changes may indicate active adversary attempts to disable security features, such as those related to malicious script execution or phish-delivered payloads. Effective implementation requires centralized logging of the Defender Operational channel and a mapping lookup to correlate ASR rule GUIDs with human-readable names.

Impact

Successful exploitation or configuration tampering in the context of these logs would allow adversaries to bypass security measures, persist in an environment, or execute unauthorized code without triggering alerts. Monitoring these events allows for the detection of policy enforcement failures and potential precursor activity to ransomware or data exfiltration events.

Recommendation

  • Enable Windows Defender Operational event logging (XML or multi-line) across all endpoints.
  • Implement a lookup table within your SIEM to map ASR rule GUIDs to descriptive rule names for improved analyst triage.
  • Create alerts for Event ID 5007 to identify unauthorized attempts to modify security settings or disable ASR rules.
  • Establish a baseline for ASR block and audit event volume to identify anomalous activity surges.

Immediate actions

Ensure Windows Defender Operational logs are ingested into the SIEM

SOC 72h

Threat Hunt

Identify spikes in Event ID 5007

T1562.001 high high confidence hunt now

Data: Event ID 5007

Enrichment needed

  • ASR Rule GUID to Name mapping lookup (Detection Engineering) Necessary for meaningful alert interpretation

Mitigations

Enable ASR rules in Block mode for known high-risk vectors

medium_term IT Operations

T1059

Detection coverage 1

Detect Microsoft Defender ASR Configuration Change

medium

Detects Event ID 5007 which indicates a configuration change to Microsoft Defender features, potentially signaling an adversary attempting to disable security controls.

sigma tactics: defense_evasion techniques: T1562.001 sources: process_creation, windows

Detection queries are available on the platform. Get full rules →