Fabian Bader · @fabian_bader
892 followers · 345 posts · Server infosec.exchange

Microsoft Defender for Endpoint Security Feature Bypass Vulnerability
CVE-2023-21809

It's enough to update your AV signatures to a version higher than 1.379.200.0

#mdav #MDE

Last updated 2 years ago

Fabian Bader · @fabian_bader
890 followers · 343 posts · Server infosec.exchange

As of 07.03.2023 (Release of signature 1.383.1159.0) tamper protection is no longer enforcing "Allow Scanning Network Files".

If you still want this to be enabled, make sure your Intune or GPO configuration has this value set.

#mdav #MDE #M365D #tamperprotection

Last updated 2 years ago

Raphael · @0x3e4
33 followers · 108 posts · Server shitcoin.land
Fabian Bader · @fabian_bader
877 followers · 331 posts · Server infosec.exchange

Update on the Server Antivirus Exclusions

Microsoft finally removed the recommendation to exclude PowerShell.exe and w3wp.exe and two others from the official documentation

techcommunity.microsoft.com/t5

#exchange #mdav #MDE

Last updated 2 years ago

Fabian Bader · @fabian_bader
864 followers · 314 posts · Server infosec.exchange

100% pure cloud based management of devices is coming closer.

See the latest Microsoft blog "Push ASR rules with Security Settings Management on Microsoft Defender for Endpoint managed devices"

techcommunity.microsoft.com/t5

#MDE #asr #mdav

Last updated 2 years ago

Fabian Bader · @fabian_bader
845 followers · 298 posts · Server infosec.exchange

Just published a small update to my "The Hitchhiker's Guide to Microsoft Defender for Endpoint exclusions" post, adding information on the new tamper protection capabilties for custom exclusions.

cloudbrothers.info/en/guide-to

#mdav #MDE #exclusions #tamperprotection

Last updated 2 years ago

Fabian Bader · @fabian_bader
823 followers · 284 posts · Server infosec.exchange

Version 1.1 of the Microsoft LNK recovery script with added support to restore from the Volume Shadow Copy Service released

github.com/microsoft/MDE-Power

#asrmagedon #MDE #mdav

Last updated 2 years ago

Fabian Bader · @fabian_bader
816 followers · 281 posts · Server infosec.exchange

My blog post from July last year became more relevant since last Friday then I had hoped.

But now is a good time to think about using the gradual rollout process for Microsoft Defender updates.

cloudbrothers.info/en/gradual-

#M365D #mdav #MDE #asrmagedon

Last updated 2 years ago

Fabian Bader · @fabian_bader
803 followers · 262 posts · Server infosec.exchange

🤩 When you use to manage your clients, tamper protection now also prevents changes to local admin merge of exclusion, which results in tamper protected exclusions 🛡️

‼️ version 4.18.2111+ is required.

techcommunity.microsoft.com/t5

#intune #mdav #MDE #security

Last updated 2 years ago

Fabian Bader · @fabian_bader
635 followers · 144 posts · Server infosec.exchange

🛡️ The Hitchhiker's Guide to Microsoft Defender for Endpoint exclusions

In this comprehensive guide I explain all available Defender for Endpoint exclusions, how they interact and which ones to use and which to avoid.

If you haven't already check it out, now is a great time.

cloudbrothers.info/en/guide-to

#MDE #mdav #exclusion #defender #DefenderForendpoint #security #av

Last updated 2 years ago

Fabian Bader · @fabian_bader
592 followers · 122 posts · Server infosec.exchange

Did you like my blog post on exclusions?

So did Microsoft and they worked with me to update their official docs article on the topic.

Go check it out, I think it's really great.

learn.microsoft.com/en-us/micr

And if you haven't yet read my blog, you still should 😁

cloudbrothers.info/guide-to-de

#MDE #security #mdav #exclusion

Last updated 2 years ago