{
"stig": {
"date": "2022-04-08",
"description": "This Security Technical Implementation Guide is published as a tool to improve the security of Department of Defense (DoD) information systems. The requirements are derived from the National Institute of Standards and Technology (NIST) 800-53 and related documents. Comments or proposed revisions to this document should be sent via email to the following address: disa.stig_spt@mail.mil.",
"findings": {
"V-213426": {
"checkid": "C-14651r820126_chk",
"checktext": "Verify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> \"Configure detection for potentially unwanted applications\" is set to \"Enabled\" and \"Block\".\n\nUse the Windows Registry Editor to navigate to the following key: \n\nHKLM\\Software\\Policies\\Microsoft\\Windows Defender\n\nIf the value \"PUAProtection\" does not exist, this is a finding.\n\nIf the value \"PUAProtection\" is REG_DWORD = 1, this is not a finding.",
"description": "After enabling this feature, PUA protection blocking takes effect on endpoint clients after the next signature update or computer restart. Signature updates take place daily under typical circumstances. PUA will be blocked and automatically quarantined.",
"fixid": "F-14649r823023_fix",
"fixtext": "Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> \"Configure Detection for Potentially Unwanted Applications\" to \"Enabled\" and \"Block\".",
"iacontrols": null,
"id": "V-213426",
"ruleID": "SV-213426r823024_rule",
"severity": "high",
"title": "Microsoft Defender AV must be configured to block the Potentially Unwanted Application (PUA) feature.",
"version": "WNDF-AV-000001"
},
"V-213427": {
"checkid": "C-14652r820128_chk",
"checktext": "Verify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> \"Turn off routine remediation\" is set to \"Disabled\" or \"Not Configured\".\n \nProcedure: Use the Windows Registry Editor to navigate to the following key: \nHKLM\\Software\\Policies\\Microsoft\\Windows Defender\n\nCriteria: If the value \"DisableRoutinelyTakingAction\" is REG_DWORD = 0, this is not a finding.\n\nIf the value does not exist, this is not a finding.\n\nIf the value is 1, this is a finding.",
"description": "This policy setting allows Microsoft Defender configuration to automatically take action on all detected threats. The action to be taken on a particular threat is determined by the combination of the policy-defined action user-defined action and the signature-defined action. If this policy setting is enabled, Microsoft Defender does not automatically take action on the detected threats but prompts users to choose from the actions available for each threat. If this policy setting is disabled or not configured, Microsoft Defender automatically takes action on all detected threats after a nonconfigurable delay of approximately five seconds.",
"fixid": "F-14650r823025_fix",
"fixtext": "Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> \"Turn off routine remediation\" to \"Disabled\" or \"Not Configured\".",
"iacontrols": null,
"id": "V-213427",
"ruleID": "SV-213427r823026_rule",
"severity": "medium",
"title": "Microsoft Defender AV must be configured to automatically take action on all detected tasks.",
"version": "WNDF-AV-000003"
},
"V-213428": {
"checkid": "C-14653r820131_chk",
"checktext": "Verify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> \"Turn off Windows Defender Antivirus\" is set to \u201cNot Configured\u201d.\n\nFor Windows 10:\nProcedure: Use the Windows Registry Editor to navigate to the following key: \nHKLM\\Software\\Policies\\Microsoft\\Windows Defender\n\nCriteria: If the value \"DisableAntiSpyware\" does not exist, this is not a finding.",
"description": "This policy setting turns off Microsoft Defender Antivirus. If this policy setting is enabled, Microsoft Defender Antivirus does not run and computers are not scanned for malware or other potentially unwanted software. \n\nWhen the setting is disabled and a third-party antivirus solution is installed, the two applications can both simultaneously try to protect the system. The two AV solutions both attempt to quarantine the same threat and will fight for access to delete the file. Users will see conflicts and the system may lock up until the two solutions finish processing. \n\nWhen the setting is not configured and a third-party antivirus solution is installed, both applications coexist on the system without conflicts. Defender Antivirus will automatically disable itself and will enable if the third-party solution stops functioning. When the setting is not configured and Defender Antivirus is the only AV solution, Defender AV will run (default state) and receive definition updates. An administrator account is needed to turn off the service. A standard user cannot disable the service.",
"fixid": "F-14651r823027_fix",
"fixtext": "For Windows 10: Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus \"Turn off Microsoft Defender Antivirus\" to \"Not Configured\". \n",
"iacontrols": null,
"id": "V-213428",
"ruleID": "SV-213428r823028_rule",
"severity": "high",
"title": "Microsoft Defender AV must be configured to run and scan for malware and other potentially unwanted software.",
"version": "WNDF-AV-000004"
},
"V-213429": {
"checkid": "C-14654r820134_chk",
"checktext": "Verify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Exclusions >> \"Path Exclusions\" is set to \"Disabled\" or \"Not Configured.\n \nProcedure: Use the Windows Registry Editor to navigate to the following key: \nHKLM\\Software\\Policies\\Microsoft\\Windows Defender\\Exclusions\n \nCriteria: If the value \"Exclusions_Paths\" does not exist, this is not a finding.",
"description": "This policy setting allows disabling of scheduled and real-time scanning for files under the paths specified or for the fully qualified resources specified. Paths should be added under the Options for this setting. Each entry must be listed as a name value pair where the name should be a string representation of a path or a fully qualified resource name. As an example, a path might be defined as: \"c:\\Windows\" to exclude all files in this directory. A fully qualified resource name might be defined as: \"C:\\Windows\\App.exe\". The value is not used and it is recommended that this be set to 0.\n\nExceptions can be made to allow file/folders that are impacting enterprise applications to be excluded from being scanned. All exclusions should be documented and approved.",
"fixid": "F-14652r823029_fix",
"fixtext": "Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Exclusions >> \"Path Exclusions\" to \"Disabled\" or \"Not Configured\".",
"iacontrols": null,
"id": "V-213429",
"ruleID": "SV-213429r823030_rule",
"severity": "medium",
"title": "Microsoft Defender AV must be configured to not exclude files for scanning.",
"version": "WNDF-AV-000005"
},
"V-213430": {
"checkid": "C-14655r820137_chk",
"checktext": "Verify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Exclusions >> \"Process Exclusions\" is set to \"Disabled\" or \"Not Configured\".\n \nProcedure: Use the Windows Registry Editor to navigate to the following key: \nHKLM\\Software\\Policies\\Microsoft\\Windows Defender\\Exclusions\n\nCriteria: If the value \"Exclusions_Processes\" does not exist, this is not a finding.",
"description": "This policy setting allows the disabling of scheduled and real-time scanning for any file opened by any of the specified processes. The process itself will not be excluded. To exclude the process, use the Path exclusion. Processes should be added under the options for this setting. Each entry must be listed as a name value pair where the name should be a string representation of the path to the process image. Note that only executables can be excluded. For example, a process might be defined as: \"c:\\windows\\app.exe\". The value is not used and it is recommended that this be set to 0.",
"fixid": "F-14653r823031_fix",
"fixtext": "Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Exclusions >> \"Process Exclusions\" to \"Disabled\" or \"Not Configured\".",
"iacontrols": null,
"id": "V-213430",
"ruleID": "SV-213430r823032_rule",
"severity": "medium",
"title": "Microsoft Defender AV must be configured to not exclude files opened by specified processes.",
"version": "WNDF-AV-000006"
},
"V-213431": {
"checkid": "C-14656r820140_chk",
"checktext": "Verify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Exclusions >> \"Turn off Auto Exclusions\" is set to \"Disabled\".\n \nProcedure: Use the Windows Registry Editor to navigate to the following key: \nHKLM\\Software\\Policies\\Microsoft\\Windows Defender\\Exclusions\n\nCriteria: If the value \"DisableAutoExclusions\" is REG_DWORD = 0, this is not a finding.",
"description": "This setting allows an administrator to specify if Automatic Exclusions feature for Server SKUs should be turned off.",
"fixid": "F-14654r823033_fix",
"fixtext": "Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Exclusions >> \"Turn off Auto Exclusions\" to \"Disabled\".",
"iacontrols": null,
"id": "V-213431",
"ruleID": "SV-213431r823034_rule",
"severity": "medium",
"title": "Microsoft Defender AV must be configured to enable the Automatic Exclusions feature.",
"version": "WNDF-AV-000007"
},
"V-213432": {
"checkid": "C-14657r820143_chk",
"checktext": "This is applicable to unclassified systems. For other systems this is NA.\n\nVerify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> MAPS >> \"Configure local setting override for reporting to Microsoft MAPS\" is set to \"Disabled\" or \"Not Configured\".\n \nProcedure: Use the Windows Registry Editor to navigate to the following key: \nHKLM\\Software\\Policies\\Microsoft\\Windows Defender\\Spynet\n\nCriteria: If the value \"LocalSettingOverrideSpynetReporting\" is REG_DWORD = 0, this is not a finding.\n\nIf the value does not exist, this is not a finding.\n\nIf the value is 1, this is a finding.",
"description": "This policy setting configures a local override for the configuration to join Microsoft MAPS. This setting can only be set by Group Policy. If this setting is enabled, the local preference setting will take priority over Group Policy. If this setting is disabled or not configured, Group Policy will take priority over the local preference setting.",
"fixid": "F-14655r823035_fix",
"fixtext": "This is applicable to unclassified systems. For other systems this is NA.\n\nSet the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> MAPS >> \"Configure local setting override for reporting to Microsoft MAPS\" to \"Disabled\" or \"Not Configured\".",
"iacontrols": null,
"id": "V-213432",
"ruleID": "SV-213432r823036_rule",
"severity": "medium",
"title": "Microsoft Defender AV must be configured to disable local setting override for reporting to Microsoft MAPS.",
"version": "WNDF-AV-000008"
},
"V-213433": {
"checkid": "C-14658r820146_chk",
"checktext": "This is applicable to unclassified systems. For other systems this is NA.\n\nVerify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> MAPS >> \"Configure the 'Block at First Sight' feature\" is set to \"Enabled\".\n \nProcedure: Use the Windows Registry Editor to navigate to the following key: \nHKLM\\Software\\Policies\\Microsoft\\Windows Defender\\Spynet\n\nCriteria: If the value \"DisableBlockAtFirstSeen\" is REG_DWORD = 0, this is not a finding.",
"description": "This feature ensures the device checks in real time with the Microsoft Active Protection Service (MAPS) before allowing certain content to be run or accessed. If this feature is disabled, the check will not occur, which will lower the protection state of the device. \n\nEnabled - The Block at First Sight setting is turned on. \nDisabled - The Block at First Sight setting is turned off. \n\nThis feature requires these Group Policy settings to be set as follows: \nMAPS >> The \"Join Microsoft MAPS\" must be enabled or the \"Block at First Sight\" feature will not function. \nMAPS >> The \"Send file samples when further analysis is required\" should be set to 1 (Send safe samples) or 3 (Send all samples). Setting to 0 (Always Prompt) will lower the protection state of the device. Setting to 2 (Never send) means the \"Block at First Sight\" feature will not function. \nReal-time Protection >> The \"Scan all downloaded files and attachments\" policy must be enabled or the \"Block at First Sight\" feature will not function. \nReal-time Protection >> Do not enable the \"Turn off real-time protection\" policy or the \"Block at First Sight\" feature will not function.",
"fixid": "F-14656r823037_fix",
"fixtext": "This is applicable to unclassified systems. For other systems this is NA.\n\nSet the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> MAPS >> \"Configure the 'Block at First Sight' feature\" to \"Enabled\".",
"iacontrols": null,
"id": "V-213433",
"ruleID": "SV-213433r823038_rule",
"severity": "medium",
"title": "Microsoft Defender AV must be configured to check in real time with MAPS before content is run or accessed.",
"version": "WNDF-AV-000009"
},
"V-213434": {
"checkid": "C-14659r820149_chk",
"checktext": "This is applicable to unclassified systems. For other systems this is NA.\n\nVerify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> MAPS >> \"Join Microsoft MAPS\" is set to \"Enabled\" and \"Advanced MAPS\" is selected from the drop-down box.\n\nProcedure: Use the Windows Registry Editor to navigate to the following key: \nHKLM\\Software\\Policies\\Microsoft\\Windows Defender\\Spynet\n\nCriteria: If the value \"SpynetReporting\" is REG_DWORD = 2, this is not a finding.",
"description": "This policy setting allows joining Microsoft MAPS. Microsoft MAPS is the online community that helps in choosing how to respond to potential threats. The community also helps stop the spread of new malicious software infections. You can choose to send basic or additional information about detected software. Additional information helps Microsoft create new definitions and protect your computer. This information can include things like location of detected items on your computer if harmful software was removed. The information will be automatically collected and sent. In some instances personal information might unintentionally be sent to Microsoft. However Microsoft will not use this information to identify you or contact you. \n\nPossible options are: \n(0x0) Disabled (default) \n(0x1) Basic membership \n(0x2) Advanced membership \n\nBasic membership will send basic information to Microsoft about software that has been detected, including where the software came from, the actions that you apply or that are applied automatically, and whether the actions were successful. Advanced membership will send, in addition to basic information, more information to Microsoft about malicious software spyware and potentially unwanted software, including the location of the software file names, how the software operates, and how it has impacted your computer. \n\nIf this setting is enabled, you will join Microsoft MAPS with the membership specified. If this setting is disabled or do not configured, you will not join Microsoft MAPS. In Windows 10, Basic membership is no longer available, so setting the value to 1 or 2 enrolls the device into Advanced membership.",
"fixid": "F-14657r823039_fix",
"fixtext": "This is applicable to unclassified systems. For other systems this is NA.\n\nSet the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> MAPS >> \"Join Microsoft MAPS\" to \"Enabled\" and select \"Advanced MAPS\" from the drop-down box.",
"iacontrols": null,
"id": "V-213434",
"ruleID": "SV-213434r823040_rule",
"severity": "medium",
"title": "Microsoft Defender AV must be configured to join Microsoft MAPS.",
"version": "WNDF-AV-000010"
},
"V-213435": {
"checkid": "C-14660r820152_chk",
"checktext": "This is applicable to unclassified systems. For other systems this is NA.\n\nVerify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> MAPS >> \"Send file samples when further analysis is required\" is set to \"Enabled\" and \"Send safe samples\" is selected from the drop-down box.\n \nProcedure: Use the Windows Registry Editor to navigate to the following key: \nHKLM\\Software\\Policies\\Microsoft\\Windows Defender\\Spynet\n\nCriteria: If the value \"SubmitSamplesConsent\" is REG_DWORD = 1, this is not a finding.",
"description": "This policy setting configures behavior of samples submission when opt-in for MAPS telemetry is set. Possible options are: \n(0x0) Always prompt\n(0x1) Send safe samples automatically \n(0x2) Never send \n(0x3) Send all samples automatically",
"fixid": "F-14658r823041_fix",
"fixtext": "This is applicable to unclassified systems. For other systems this is NA.\n\nSet the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> MAPS >> \"Send file samples when further analysis is required\" to \"Enabled\" and select \"Send safe samples\" from the drop-down box.",
"iacontrols": null,
"id": "V-213435",
"ruleID": "SV-213435r823042_rule",
"severity": "medium",
"title": "Microsoft Defender AV must be configured to only send safe samples for MAPS telemetry.",
"version": "WNDF-AV-000011"
},
"V-213436": {
"checkid": "C-14661r820155_chk",
"checktext": "Verify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Network Inspection System >> \"Turn on protocol recognition\" is set to \"Enabled\" or \"Not Configured\".\n \nProcedure: Use the Windows Registry Editor to navigate to the following key:\nHKLM\\Software\\Policies\\Microsoft\\Windows Defender\\NIS\n\nCriteria: If the value \"DisableProtocolRecognition\" is REG_DWORD = 0, this is not a finding.\n\nIf the value does not exist, this is not a finding.\n\nIf the value is 1, this is a finding.",
"description": "This policy setting allows the configuration of protocol recognition for network protection against exploits of known vulnerabilities. If this setting is enabled or not configured, protocol recognition will be enabled. If this setting is disabled, protocol recognition will be disabled.",
"fixid": "F-14659r823043_fix",
"fixtext": "Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Network Inspection System >> \"Turn on protocol recognition\" to \"Enabled\" or \"Not Configured\".",
"iacontrols": null,
"id": "V-213436",
"ruleID": "SV-213436r823044_rule",
"severity": "medium",
"title": "Microsoft Defender AV must be configured for protocol recognition for network protection.",
"version": "WNDF-AV-000012"
},
"V-213437": {
"checkid": "C-14662r820158_chk",
"checktext": "Verify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Real-time Protection >> \"Configure local setting override for monitoring file and program activity on your computer\" is set to \"Disabled\" or \"Not Configured\".\n \nProcedure: Use the Windows Registry Editor to navigate to the following key: \nHKLM\\Software\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\n\nCriteria: If the value \"LocalSettingOverrideDisableOnAccessProtection\" is REG_DWORD = 0, this is not a finding.\n\nIf the value does not exist, this is not a finding.\n\nIf the value is 1, this is a finding.",
"description": "This policy setting configures a local override for the configuration of monitoring for file and program activity on your computer. This setting can only be set by Group Policy. If this setting is enabled, the local preference setting will take priority over Group Policy. If this setting is disabled or not configured, Group Policy will take priority over the local preference setting.",
"fixid": "F-14660r823045_fix",
"fixtext": "Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Real-time Protection >> \"Configure local setting override for monitoring file and program activity on your computer\" to \"Disabled\" or \"Not Configured\".",
"iacontrols": null,
"id": "V-213437",
"ruleID": "SV-213437r823046_rule",
"severity": "medium",
"title": "Microsoft Defender AV must be configured to not allow local override of monitoring for file and program activity.",
"version": "WNDF-AV-000013"
},
"V-213438": {
"checkid": "C-14663r820161_chk",
"checktext": "Verify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Real-time Protection >> \"Configure local setting override for monitoring for incoming and outgoing file activity\" is set to \"Disabled\" or \"Not Configured\".\n \nProcedure: Use the Windows Registry Editor to navigate to the following key: \nHKLM\\Software\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\n\nCriteria: If the value \"LocalSettingOverrideRealtimeScanDirection\" is REG_DWORD = 0, this is not a finding.\n\nIf the value does not exist, this is not a finding.\n\nIf the value is 1, this is a finding.",
"description": "This policy setting configures a local override for the configuration of monitoring for incoming and outgoing file activity. This setting can only be set by Group Policy. If this setting is enabled, the local preference setting will take priority over Group Policy. If this setting is disabled or not configured, Group Policy will take priority over the local preference setting.",
"fixid": "F-14661r823047_fix",
"fixtext": "Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Real-time Protection >> \"Configure local setting override for monitoring for incoming and outgoing file activity\" to \"Disabled\" or \"Not Configured\".",
"iacontrols": null,
"id": "V-213438",
"ruleID": "SV-213438r823048_rule",
"severity": "medium",
"title": "Microsoft Defender AV must be configured to not allow override of monitoring for incoming and outgoing file activity.",
"version": "WNDF-AV-000014"
},
"V-213439": {
"checkid": "C-14664r820164_chk",
"checktext": "Verify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Real-time Protection >> \"Configure local setting override for scanning all downloaded files and attachments\" is set to \"Disabled\" or \"Not Configured\".\n \nProcedure: Use the Windows Registry Editor to navigate to the following key: \nHKLM\\Software\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\n\nCriteria: If the value \"LocalSettingOverrideDisableIOAVProtection\" is REG_DWORD = 0, this is not a finding.\n\nIf the value does not exist, this is not a finding.\n\nIf the value is 1, this is a finding.",
"description": "This policy setting configures a local override for the configuration of scanning for all downloaded files and attachments. This setting can only be set by Group Policy. If this setting is enabled, the local preference setting will take priority over Group Policy. If this setting is disabled or not configured, Group Policy will take priority over the local preference setting.",
"fixid": "F-14662r823049_fix",
"fixtext": "Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Real-time Protection >> \"Configure local setting override for scanning all downloaded files and attachments\" to \"Disabled\" or \"Not Configured\".",
"iacontrols": null,
"id": "V-213439",
"ruleID": "SV-213439r823050_rule",
"severity": "medium",
"title": "Microsoft Defender AV must be configured to not allow override of scanning for downloaded files and attachments.",
"version": "WNDF-AV-000015"
},
"V-213440": {
"checkid": "C-14665r820167_chk",
"checktext": "Verify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Real-time Protection >> \"Configure local setting override for turn on behavior monitoring\" is set to \"Disabled\" or \"Not Configured\".\n \nProcedure: Use the Windows Registry Editor to navigate to the following key: \nHKLM\\Software\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\n\nCriteria: If the value \"LocalSettingOverrideDisableBehaviorMonitoring\" is REG_DWORD = 0, this is not a finding.\n\nIf the value does not exist, this is not a finding.\n\nIf the value is 1, this is a finding.",
"description": "This policy setting configures a local override for the configuration of behavior monitoring. This setting can only be set by Group Policy. If this setting is enabled, the local preference setting will take priority over Group Policy. If this setting is disabled or not configured, Group Policy will take priority over the local preference setting.",
"fixid": "F-14663r823051_fix",
"fixtext": "Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Real-time Protection >> \"Configure local setting override for turn on behavior monitoring\" to \"Disabled\" or \"Not Configured\".",
"iacontrols": null,
"id": "V-213440",
"ruleID": "SV-213440r823052_rule",
"severity": "medium",
"title": "Microsoft Defender AV must be configured to not allow override of behavior monitoring.",
"version": "WNDF-AV-000016"
},
"V-213441": {
"checkid": "C-14666r820170_chk",
"checktext": "Verify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Real-time Protection >> \"Configure local setting override to turn on real-time protection\" is set to \"Disabled\" or \"Not Configured\".\n \nProcedure: Use the Windows Registry Editor to navigate to the following key: \nHKLM\\Software\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\n\nCriteria: If the value \"LocalSettingOverrideDisableRealtimeMonitoring\" is REG_DWORD = 0, this is not a finding.\n\nIf the value does not exist, this is not a finding.\n\nIf the value is 1, this is a finding.",
"description": "This policy setting configures a local override for the configuration to turn on real-time protection. This setting can only be set by Group Policy. If this setting is enabled, the local preference setting will take priority over Group Policy. If this setting is disabled or not configured, Group Policy will take priority over the local preference setting.",
"fixid": "F-14664r823053_fix",
"fixtext": "Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Real-time Protection >> \"Configure local setting override to turn on real-time protection\" to \"Disabled\" or \"Not Configured\".",
"iacontrols": null,
"id": "V-213441",
"ruleID": "SV-213441r823054_rule",
"severity": "medium",
"title": "Microsoft Defender AV Group Policy settings must take priority over the local preference settings.",
"version": "WNDF-AV-000017"
},
"V-213442": {
"checkid": "C-14667r820173_chk",
"checktext": "Verify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Real-time Protection >> \"Configure monitoring for incoming and outgoing file and program activity\" is set to \"Disabled\" or \"Not Configured\".\n \nProcedure: Use the Windows Registry Editor to navigate to the following key: \nHKLM\\Software\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\n\nCriteria: If the value \"RealtimeScanDirection\" is REG_DWORD = 0, this is not a finding.\n\nIf the value does not exist, this is not a finding.\n\nIf the value is 1 or 2, this is a finding.",
"description": "This policy setting allows the configuration of monitoring for incoming and outgoing files without having to turn off monitoring entirely. It is recommended for use on servers that have a lot of incoming and outgoing file activity but for performance reasons need to have scanning disabled for a particular scan direction. The appropriate configuration should be evaluated based on the server role. Note that this configuration is only honored for NTFS volumes. For any other file system type, full monitoring of file and program activity will be present on those volumes. \n\nThe options for this setting are mutually exclusive: \n0 = Scan incoming and outgoing files (default) \n1 = Scan incoming files only \n2 = Scan outgoing files only \n\nAny other value, or if the value does not exist, resolves to the default (0). If this setting is enabled, the specified type of monitoring will be enabled. If this setting is disabled or not configured, monitoring for incoming and outgoing files will be enabled.",
"fixid": "F-14665r823055_fix",
"fixtext": "Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Real-time Protection >> \"Configure monitoring for incoming and outgoing file and program activity\" to \"Disabled\" or \"Not Configured\".",
"iacontrols": null,
"id": "V-213442",
"ruleID": "SV-213442r823056_rule",
"severity": "medium",
"title": "Microsoft Defender AV must monitor for incoming and outgoing files.",
"version": "WNDF-AV-000018"
},
"V-213443": {
"checkid": "C-14668r820176_chk",
"checktext": "Verify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Real-time Protection >> \"Monitor file and program activity on your computer to be scanned\" is set to \"Enabled\" or \"Not Configured\".\n \nProcedure: Use the Windows Registry Editor to navigate to the following key: \nHKLM\\Software\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\n\nCriteria: If the value \"DisableOnAccessProtection\" is REG_DWORD = 0, this is not a finding.\n\nIf the value does not exist, this is not a finding.\n\nIf the value is 1, this is a finding.",
"description": "This policy setting allows configuration of monitoring for file and program activity. If this setting is enabled or not configured, monitoring for file and program activity will be enabled. If this setting is disabled, monitoring for file and program activity will be disabled.",
"fixid": "F-14666r823057_fix",
"fixtext": "Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Real-time Protection >> \"Monitor file and program activity on your computer\" to \"Enabled\" or \"Not Configured\".",
"iacontrols": null,
"id": "V-213443",
"ruleID": "SV-213443r823058_rule",
"severity": "medium",
"title": "Microsoft Defender AV must be configured to monitor for file and program activity.",
"version": "WNDF-AV-000019"
},
"V-213444": {
"checkid": "C-14669r820179_chk",
"checktext": "Verify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Real-time Protection >> \"Scan all downloaded files and attachments\" is set to \"Enabled\" or \"Not Configured\".\n \nProcedure: Use the Windows Registry Editor to navigate to the following key: \nHKLM\\Software\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\n\nCriteria: If the value \"DisableIOAVProtection\" is REG_DWORD = 0, this is not a finding.\n\nIf the value does not exist, this is not a finding.\n\nIf the value is 1, this is a finding.",
"description": "This policy setting allows configuration of scanning for all downloaded files and attachments. If this setting is enabled or not configured, scanning for all downloaded files and attachments will be enabled. If this setting is disabled, scanning for all downloaded files and attachments will be disabled.",
"fixid": "F-14667r823059_fix",
"fixtext": "Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Real-time Protection >> \"Scan all downloaded files and attachments\" to \"Enabled\" or \"Not Configured\".",
"iacontrols": null,
"id": "V-213444",
"ruleID": "SV-213444r823060_rule",
"severity": "medium",
"title": "Microsoft Defender AV must be configured to scan all downloaded files and attachments.",
"version": "WNDF-AV-000020"
},
"V-213445": {
"checkid": "C-14670r820182_chk",
"checktext": "Verify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Real-time Protection >> \"Turn off real-time protection\" is set to \"Disabled\" or \"Not Configured\".\n \nProcedure: Use the Windows Registry Editor to navigate to the following key: \nHKLM\\Software\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\n\nCriteria: If the value \"DisableRealtimeMonitoring\" is REG_DWORD = 0, this is not a finding.\n\nIf the value does not exist, this is not a finding.\n\nIf the value is 1, this is a finding.",
"description": "This policy setting turns off real-time protection prompts for known malware detection. Microsoft Defender Antivirus alerts when malware or potentially unwanted software attempts to install itself or to run on your computer. If this policy setting is enabled, Microsoft Defender Antivirus will not prompt users to take actions on malware detections. If this policy setting is disabled or not configured, Microsoft Defender Antivirus will prompt users to take actions on malware detections.",
"fixid": "F-14668r823061_fix",
"fixtext": "Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Real-time Protection >> \"Turn off real-time protection\" to \"Disabled\" or \"Not Configured\".",
"iacontrols": null,
"id": "V-213445",
"ruleID": "SV-213445r823062_rule",
"severity": "medium",
"title": "Microsoft Defender AV must be configured to always enable real-time protection.",
"version": "WNDF-AV-000021"
},
"V-213446": {
"checkid": "C-14671r820185_chk",
"checktext": "Verify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Real-time Protection >> \"Turn on behavior monitoring\" is set to \"Enabled\" or \"Not Configured\".\n \nProcedure: Use the Windows Registry Editor to navigate to the following key: \nHKLM\\Software\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\n\nCriteria: If the value \"DisableBehaviorMonitoring\" is REG_DWORD = 0, this is not a finding.\n\nIf the value does not exist, this is not a finding.\n\nIf the value is 1, this is a finding.",
"description": "This policy setting allows configuration of behavior monitoring. If this setting is enabled or not configured, behavior monitoring will be enabled. If this setting is disabled, behavior monitoring will be disabled.",
"fixid": "F-14669r820186_fix",
"fixtext": "Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Windows Defender Antivirus >> Real-time Protection >> \"Turn on behavior monitoring\" to \"Enabled \" or \"Not Configured\".",
"iacontrols": null,
"id": "V-213446",
"ruleID": "SV-213446r823063_rule",
"severity": "medium",
"title": "Microsoft Defender AV must be configured to enable behavior monitoring.",
"version": "WNDF-AV-000022"
},
"V-213447": {
"checkid": "C-14672r820188_chk",
"checktext": "Verify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Real-time Protection >> \"Turn on process scanning whenever real-time protection is enabled\" is set to \"Enabled\" or \"Not Configured\".\n \nProcedure: Use the Windows Registry Editor to navigate to the following key: \nHKLM\\Software\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\n\nCriteria: If the value \"DisableScanOnRealtimeEnable\" is REG_DWORD = 0, this is not a finding.\n\nIf the value does not exist, this is not a finding.\n\nIf the value is 1, this is a finding.",
"description": "This policy setting allows the configuration of process scanning when real-time protection is turned on. This helps to catch malware, which could start when real-time protection is turned off. If this setting is enabled or not configured, a process scan will be initiated when real-time protection is turned on. If this setting is disabled, a process scan will not be initiated when real-time protection is turned on.",
"fixid": "F-14670r823064_fix",
"fixtext": "Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Real-time Protection >> \"Turn on process scanning whenever real-time protection is enabled\" to \"Enabled\" or \"Not Configured\".",
"iacontrols": null,
"id": "V-213447",
"ruleID": "SV-213447r823065_rule",
"severity": "medium",
"title": "Microsoft Defender AV must be configured to process scanning when real-time protection is enabled.",
"version": "WNDF-AV-000023"
},
"V-213448": {
"checkid": "C-14673r820191_chk",
"checktext": "Verify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Scan >> \"Scan archive files\" is set to \"Enabled\" or \"Not Configured\".\n \nProcedure: Use the Windows Registry Editor to navigate to the following key: \nHKLM\\Software\\Policies\\Microsoft\\Windows Defender\\Scan\n\nCriteria: If the value \"DisableArchiveScanning\" is REG_DWORD = 0, this is not a finding.\n\nIf the value does not exist, this is not a finding.\n\nIf the value is 1, this is a finding.",
"description": "This policy setting allows the configuration of scans for malicious software and unwanted software in archive files such as .ZIP or .CAB files. If this setting is enabled or not configured, archive files will be scanned. If this setting is disabled, archive files will not be scanned.",
"fixid": "F-14671r823066_fix",
"fixtext": "Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Scan >> \"Scan archive files\" to \"Enabled \" or \"Not Configured\".",
"iacontrols": null,
"id": "V-213448",
"ruleID": "SV-213448r823067_rule",
"severity": "medium",
"title": "Microsoft Defender AV must be configured to scan archive files.",
"version": "WNDF-AV-000024"
},
"V-213449": {
"checkid": "C-14674r820194_chk",
"checktext": "Verify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Scan >> \"Scan removable drives\" is set to \"Enabled\".\n \nProcedure: Use the Windows Registry Editor to navigate to the following key: \nHKLM\\Software\\Policies\\Microsoft\\Windows Defender\\Scan\n\nCriteria: If the value \"DisableRemovableDriveScanning\" is REG_DWORD = 0, this is not a finding.",
"description": "This policy setting allows the management of whether or not to scan for malicious software and unwanted software in the contents of removable drives such as USB flash drives when running a full scan. If this setting is enabled, removable drives will be scanned during any type of scan. If this setting is disabled or not configured, removable drives will not be scanned during a full scan. Removable drives may still be scanned during quick scan and custom scan.",
"fixid": "F-14672r820195_fix",
"fixtext": "Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Windows Defender Antivirus >> Scan >> \"Scan removable drives\" to \"Enabled\".",
"iacontrols": null,
"id": "V-213449",
"ruleID": "SV-213449r823068_rule",
"severity": "medium",
"title": "Microsoft Defender AV must be configured to scan removable drives.",
"version": "WNDF-AV-000025"
},
"V-213450": {
"checkid": "C-14675r820197_chk",
"checktext": "Verify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Scan >> \"Specify the day of the week to run a scheduled scan\" is set to \"Enabled\" and anything other than \"Never\" is selected in the drop-down box.\n \nProcedure: Use the Windows Registry Editor to navigate to the following key: \nHKLM\\Software\\Policies\\Microsoft\\Windows Defender\\Scan\n\nCriteria: If the value \"ScheduleDay\" is REG_DWORD = 0x8, this is a finding.\n\nValues of 0x0 through 0x7 are acceptable and not a finding.",
"description": "This policy setting allows specifying the day of the week on which to perform a scheduled scan. The scan can also be configured to run every day or to never run at all. This setting can be configured with the following ordinal number values: \n(0x0) Every Day \n(0x1) Sunday \n(0x2) Monday \n(0x3) Tuesday \n(0x4) Wednesday \n(0x5) Thursday \n(0x6) Friday \n(0x7) Saturday \n(0x8) Never (default) \n\nIf this setting is enabled, a scheduled scan will run at the frequency specified. If this setting is disabled or not configured, a scheduled scan will run at a default frequency.",
"fixid": "F-14673r823069_fix",
"fixtext": "Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Scan >> \"Specify the day of the week to run a scheduled scan\" to \"Enabled \" and select anything other than \"Never\" in the drop-down box.",
"iacontrols": null,
"id": "V-213450",
"ruleID": "SV-213450r823070_rule",
"severity": "medium",
"title": "Microsoft Defender AV must be configured to perform a weekly scheduled scan.",
"version": "WNDF-AV-000026"
},
"V-213451": {
"checkid": "C-14676r820200_chk",
"checktext": "Verify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Scan >> \"Turn on e-mail scanning\" is set to \"Enabled\".\n \nProcedure: Use the Windows Registry Editor to navigate to the following key: \nHKLM\\Software\\Policies\\Microsoft\\Windows Defender\\Scan\n\nCriteria: If the value \"DisableEmailScanning\" is REG_DWORD = 0, this is not a finding.",
"description": "This policy setting allows the configuration of e-mail scanning. When e-mail scanning is enabled, the engine will parse the mailbox and mail files according to their specific format in order to analyze the mail bodies and attachments. Several e-mail formats are currently supported, for example: pst (Outlook), dbx mbx mime (Outlook Express), binhex (Mac). If this setting is enabled, e-mail scanning will be enabled. If this setting is disabled or not configured, e-mail scanning will be disabled.",
"fixid": "F-14674r823071_fix",
"fixtext": "Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Scan >> \"Turn on e-mail scanning\" to \"Enabled\".",
"iacontrols": null,
"id": "V-213451",
"ruleID": "SV-213451r823072_rule",
"severity": "medium",
"title": "Microsoft Defender AV must be configured to turn on e-mail scanning.",
"version": "WNDF-AV-000027"
},
"V-213452": {
"checkid": "C-14677r820203_chk",
"checktext": "Verify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Security Intelligence Updates >> \"Define the number of days before spyware security intelligence considered out of date\" is set to \"Enabled\" and \"7\" or less is selected in the drop-down box (excluding \"0\", which is unacceptable).\n\nIf third-party antispyware is installed and up to date, the Windows Defender AV spyware age requirement will be NA.\n\nProcedure: Use the Windows Registry Editor to navigate to the following key: \nHKLM\\Software\\Policies\\Microsoft\\Windows Defender\\Signature Updates\n\nCriteria: If the value \"ASSignatureDue\" is REG_DWORD = 7, this is not a finding.\n\nA value of 1 - 6 is also acceptable and not a finding.\n\nA value of 0 is a finding.\n\nA value higher than 7 is a finding.",
"description": "This policy setting allows defining the number of days that must pass before spyware definitions are considered out of date. If definitions are determined to be out of date, this state may trigger several additional actions, including falling back to an alternative update source or displaying a warning icon in the user interface. By default this value is set to 14 days. \n\nIf this setting is enabled, spyware definitions will be considered out of date after the number of days specified have passed without an update. If this setting is disabled or not configured, spyware definitions will be considered out of date after the default number of days have passed without an update.",
"fixid": "F-14675r820204_fix",
"fixtext": "Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Windows Defender Antivirus >> Signature Updates >> \"Define the number of days before spyware definitions are considered out of date\" to \"Enabled\" and select \"7\" or less in the drop-down box.\n\nDo not select a value of 0. This disables the option.",
"iacontrols": null,
"id": "V-213452",
"ruleID": "SV-213452r823073_rule",
"severity": "high",
"title": "Microsoft Defender AV spyware definition age must not exceed 7 days.",
"version": "WNDF-AV-000028"
},
"V-213453": {
"checkid": "C-14678r820206_chk",
"checktext": "Verify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >>Security Intelligence Updates >> \"Define the number of days before virus security intelligence considered out of date\" is set to \"Enabled\" and \"7\" or less is selected in the drop-down box (excluding \"0\", which is unacceptable).\n\nIf third-party antivirus protection is installed and up to date, the Windows Defender Antivirus age requirement is NA.\n\nProcedure: Use the Windows Registry Editor to navigate to the following key: \nHKLM\\Software\\Policies\\Microsoft\\Windows Defender\\Signature Updates\n\nCriteria: If the value \"AVSignatureDue\" is REG_DWORD = 7, this is not a finding.\n\nA value of 1 - 6 is also acceptable and not a finding.\n\nA value of 0 is a finding.\n\nA value higher than 7 is a finding.",
"description": "This policy setting allows defining the number of days that must pass before virus definitions are considered out of date. If definitions are determined to be out of date, this state may trigger several additional actions, including falling back to an alternative update source or displaying a warning icon in the user interface. By default, this value is set to 14 days. \n\nIf this setting is enabled, virus definitions will be considered out of date after the number of days specified have passed without an update. If this setting is disabled or not configured, virus definitions will be considered out of date after the default number of days have passed without an update.",
"fixid": "F-14676r823074_fix",
"fixtext": "Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Signature Updates >> \"Define the number of days before virus definitions are considered out of date\" to \"Enabled\" and select \"7\" or less in the drop-down box.\n\nDo not select a value of 0. This disables the option.",
"iacontrols": null,
"id": "V-213453",
"ruleID": "SV-213453r823075_rule",
"severity": "high",
"title": "Microsoft Defender AV virus definition age must not exceed 7 days.",
"version": "WNDF-AV-000029"
},
"V-213454": {
"checkid": "C-14679r820209_chk",
"checktext": "Verify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Security Intelligence Updates >> \"Specify the day of the week to check for security intelligence updates\" is set to \"Enabled\" and \"Every Day\" is selected in the drop-down box.\n \nProcedure: Use the Windows Registry Editor to navigate to the following key: \nHKLM\\Software\\Policies\\Microsoft\\Windows Defender\\Signature Updates\n\nCriteria: If the value \"ScheduleDay\" is REG_DWORD = 0, this is not a finding.",
"description": "This policy setting allows specifying the day of the week on which to check for definition updates. The check can also be configured to run every day or to never run at all. This setting can be configured with the following ordinal number values: \n(0x0) Every Day (default) \n(0x1) Sunday \n(0x2) Monday \n(0x3) Tuesday \n(0x4) Wednesday \n(0x5) Thursday \n(0x6) Friday \n(0x7) Saturday \n(0x8) Never \n\nIf this setting is enabled, the check for definition updates will occur at the frequency specified. If this setting is disabled or not configured, the check for definition updates will occur at a default frequency.",
"fixid": "F-14677r823076_fix",
"fixtext": "Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Signature Updates >> \"Specify the day of the week to check for definition updates\" to \"Enabled\" and select \"Every Day\" in the drop-down box.",
"iacontrols": null,
"id": "V-213454",
"ruleID": "SV-213454r823077_rule",
"severity": "medium",
"title": "Microsoft Defender AV must be configured to check for definition updates daily.",
"version": "WNDF-AV-000030"
},
"V-213455": {
"checkid": "C-14680r820212_chk",
"checktext": "Verify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Threats >> \"Specify threat alert levels at which default action should not be taken when detected\" is set to \"Enabled\". \n\nClick the \u201cShow\u2026\u201d box option and verify the \"Value name\" field contains a value of \"5\" and the \"Value\" field contains \"2\". A value of \"3\" in the \"Value\" field is more restrictive and also an acceptable value.\n \nProcedure: Use the Windows Registry Editor to navigate to the following key: \nHKLM\\Software\\Policies\\Microsoft\\Windows Defender\\Threats\\ThreatSeverityDefaultAction\n\nCriteria: If the value \"5\" is REG_SZ = 2 (or 3), this is not a finding.\n",
"description": "This policy setting allows the customization of which automatic remediation action will be taken for each threat alert level. Threat alert levels should be added under the Options for this setting. Each entry must be listed as a name value pair. The name defines a threat alert level. The value contains the action ID for the remediation action that should be taken. \n\nValid threat alert levels are: \n1 = Low \n2 = Medium \n4 = High \n5 = Severe \n\nValid remediation action values are: \n2 = Quarantine \n3 = Remove \n6 = Ignore",
"fixid": "F-14678r823078_fix",
"fixtext": "Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Threats >> \"Specify threat alert levels at which default action should not be taken when detected\" to \"Enabled\". \n\nSelect the \"Show\u2026\" option box and enter \"5\" in the \"Value name\" field and enter \"2\" in the \"Value\" field.",
"iacontrols": null,
"id": "V-213455",
"ruleID": "SV-213455r823079_rule",
"severity": "medium",
"title": "Microsoft Defender AV must be configured for automatic remediation action to be taken for threat alert level Severe.",
"version": "WNDF-AV-000031"
},
"V-213456": {
"checkid": "C-14681r820215_chk",
"checktext": "This setting is applicable starting with v1709 of Windows 10. It is NA for prior versions.\n\nVerify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Microsoft Defender Exploit Guard >> Attack Surface Reduction >> \"Configure Attack Surface Reduction rules\" is set to \"Enabled\u201d. Click \"Show...\". Verify the rule ID in the Value name column and the desired state in the Value column is set as follows:\nValue name: BE9BA2D9-53EA-4CDC-84E5-9B1EEEE46550\nValue: 1\n\nProcedure: Use the Windows Registry Editor to navigate to the following key: \nHKLM\\Software\\Policies\\Microsoft\\Windows Defender\\Windows Defender Exploit Guard\\ASR\\Rules\n\nCriteria: If the value \"BE9BA2D9-53EA-4CDC-84E5-9B1EEEE46550\" is REG_SZ = 1, this is not a finding.",
"description": "This rule blocks the following file types from being run or launched from an email seen in either Microsoft Outlook or webmail (such as Gmail.com or Outlook.com):\nExecutable files (such as .exe, .dll, or .scr)\nScript files (such as a PowerShell .ps, VisualBasic .vbs, or JavaScript .js file)\nScript archive files",
"fixid": "F-14679r823080_fix",
"fixtext": "Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Windows Defender Exploit Guard >> Attack Surface Reduction >> \"Configure Attack Surface Reduction rules\" to \"Enabled\". \n\nClick \"Show...\". Set the Value name to \"BE9BA2D9-53EA-4CDC-84E5-9B1EEEE46550\" and the Value to \"1\".",
"iacontrols": null,
"id": "V-213456",
"ruleID": "SV-213456r823081_rule",
"severity": "medium",
"title": "Microsoft Defender AV must be configured to block executable content from email client and webmail.",
"version": "WNDF-AV-000032"
},
"V-213457": {
"checkid": "C-14682r820218_chk",
"checktext": "This setting is applicable starting with v1709 of Windows 10. It is NA for prior versions.\n\nVerify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Microsoft Defender Exploit Guard >> Attack Surface Reduction >> \"Configure Attack Surface Reduction rules\" is set to \"Enabled\u201d. Click \"Show...\". Verify the rule ID in the Value name column and the desired state in the Value column is set as follows:\nValue name: D4F940AB-401B-4EFC-AADC-AD5F3C50688A\nValue: 1\n\nProcedure: Use the Windows Registry Editor to navigate to the following key: \nHKLM\\Software\\Policies\\Microsoft\\Windows Defender\\Windows Defender Exploit Guard\\ASR\\Rules\n\nCriteria: If the value \"D4F940AB-401B-4EFC-AADC-AD5F3C50688A\" is REG_SZ = 1, this is not a finding.",
"description": "Office apps, such as Word or Excel, will not be allowed to create child processes. This is a typical malware behavior, especially for macro-based attacks that attempt to use Office apps to launch or download malicious executables.",
"fixid": "F-14680r823082_fix",
"fixtext": "Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Windows Defender Exploit Guard >> Attack Surface Reduction >> \"Configure Attack Surface Reduction rules\" to \"Enabled\". \n\nClick \"Show...\". Set the Value name to \"D4F940AB-401B-4EFC-AADC-AD5F3C50688A\" and the Value to \"1\".",
"iacontrols": null,
"id": "V-213457",
"ruleID": "SV-213457r823083_rule",
"severity": "medium",
"title": "Microsoft Defender AV must be configured block Office applications from creating child processes.",
"version": "WNDF-AV-000033"
},
"V-213458": {
"checkid": "C-14683r820221_chk",
"checktext": "This setting is applicable starting with v1709 of Windows 10. It is NA for prior versions.\n\nVerify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Microsoft Defender Exploit Guard >> Attack Surface Reduction >> \"Configure Attack Surface Reduction rules\" is set to \"Enabled\u201d. Click \"Show...\". Verify the rule ID in the Value name column and the desired state in the Value column is set as follows:\nValue name: 3B576869-A4EC-4529-8536-B80A7769E899\nValue: 1\n \nProcedure: Use the Windows Registry Editor to navigate to the following key: \nHKLM\\Software\\Policies\\Microsoft\\Windows Defender\\Windows Defender Exploit Guard\\ASR\\Rules\n\nCriteria: If the value \"3B576869-A4EC-4529-8536-B80A7769E899\" is REG_SZ = 1, this is not a finding.",
"description": "This rule targets typical behaviors used by suspicious and malicious add-ons and scripts (extensions) that create or launch executable files. This is a typical malware technique. Extensions will be blocked from being used by Office apps. Typically these extensions use the Windows Scripting Host (.wsh files) to run scripts that automate certain tasks or provide user-created add-on features.",
"fixid": "F-14681r823084_fix",
"fixtext": "Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Windows Defender Exploit Guard >> Attack Surface Reduction >> \"Configure Attack Surface Reduction rules\" to \"Enabled\". \n\nClick \"Show...\". Set the Value name to \"3B576869-A4EC-4529-8536-B80A7769E899\" and the Value to \"1\".",
"iacontrols": null,
"id": "V-213458",
"ruleID": "SV-213458r823085_rule",
"severity": "medium",
"title": "Microsoft Defender AV must be configured block Office applications from creating executable content.",
"version": "WNDF-AV-000034"
},
"V-213459": {
"checkid": "C-14684r820224_chk",
"checktext": "This setting is applicable starting with v1709 of Windows 10. It is NA for prior versions.\n\nVerify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Microsoft Defender Exploit Guard >> Attack Surface Reduction >> \"Configure Attack Surface Reduction rules\" is set to \"Enabled\u201d. Click \"Show...\". Verify the rule ID in the Value name column and the desired state in the Value column is set as follows:\nValue name: 75668C1F-73B5-4CF0-BB93-3ECF5CB7CC84\nValue: 1\n\nProcedure: Use the Windows Registry Editor to navigate to the following key: \nHKLM\\Software\\Policies\\Microsoft\\Windows Defender\\Windows Defender Exploit Guard\\ASR\\Rules\n\nCriteria: If the value \"75668C1F-73B5-4CF0-BB93-3ECF5CB7CC84\" is REG_SZ = 1, this is not a finding.",
"description": "Office apps, such as Word, Excel, or PowerPoint, will not be able to inject code into other processes. This is typically used by malware to run malicious code in an attempt to hide the activity from antivirus scanning engines.",
"fixid": "F-14682r823086_fix",
"fixtext": "Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Windows Defender Exploit Guard >> Attack Surface Reduction >> \"Configure Attack Surface Reduction rules\" to \"Enabled\".\n\nClick \"Show...\". Set the Value name to \"75668C1F-73B5-4CF0-BB93-3ECF5CB7CC84\" and the Value to \"1\".",
"iacontrols": null,
"id": "V-213459",
"ruleID": "SV-213459r823087_rule",
"severity": "medium",
"title": "Microsoft Defender AV must be configured to block Office applications from injecting into other processes.",
"version": "WNDF-AV-000035"
},
"V-213460": {
"checkid": "C-14685r820227_chk",
"checktext": "This setting is applicable starting with v1709 of Windows 10. It is NA for prior versions.\n\nVerify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Microsoft Defender Exploit Guard >> Attack Surface Reduction >> \"Configure Attack Surface Reduction rules\" is set to \"Enabled\". Click \"Show...\". Verify the rule ID in the Value name column and the desired state in the Value column is set as follows:\nValue name: D3E037E1-3EB8-44C8-A917-57927947596D \nValue: 1\n\nProcedure: Use the Windows Registry Editor to navigate to the following key: \nHKLM\\Software\\Policies\\Microsoft\\Windows Defender\\Windows Defender Exploit Guard\\ASR\\Rules\n\nCriteria: If the value \"D3E037E1-3EB8-44C8-A917-57927947596D\" is REG_SZ = 1, this is not a finding.",
"description": "JavaScript and VBScript scripts can be used by malware to launch other malicious apps. This rule prevents these scripts from being allowed to launch apps, thus preventing malicious use of the scripts to spread malware and infect machines.",
"fixid": "F-14683r823088_fix",
"fixtext": "Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Windows Defender Exploit Guard >> Attack Surface Reduction >> \"Configure Attack Surface Reduction rules\" to \"Enabled\".\n\nClick \"Show...\". Set the Value name to \"D3E037E1-3EB8-44C8-A917-57927947596D\" and the Value to \"1\".",
"iacontrols": null,
"id": "V-213460",
"ruleID": "SV-213460r823089_rule",
"severity": "medium",
"title": "Microsoft Defender AV must be configured to impede JavaScript and VBScript to launch executables.",
"version": "WNDF-AV-000036"
},
"V-213461": {
"checkid": "C-14686r820230_chk",
"checktext": "This setting is applicable starting with v1709 of Windows 10. It is NA for prior versions.\n\nVerify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Windows Defender Exploit Guard >> Attack Surface Reduction >> \"Configure Attack Surface Reduction rules\" is set to \"Enabled\u201d. Click \"Show...\". Verify the rule ID in the Value name column and the desired state in the Value column is set as follows:\nValue name: 5BEB7EFE-FD9A-4556-801D-275E5FFC04CC\nValue: 1\n\nProcedure: Use the Windows Registry Editor to navigate to the following key: \nHKLM\\Software\\Policies\\Microsoft\\Windows Defender\\Windows Defender Exploit Guard\\ASR\\Rules\n\nCriteria: If the value \"5BEB7EFE-FD9A-4556-801D-275E5FFC04CC\" is REG_SZ = 1, this is not a finding.",
"description": "Malware and other threats can attempt to obfuscate or hide their malicious code in some script files. This rule prevents scripts that appear to be obfuscated from running. It uses the AntiMalwareScanInterface (AMSI) to determine if a script is potentially obfuscated and then blocks such a script or blocks scripts when an attempt is made to access them.",
"fixid": "F-14684r823090_fix",
"fixtext": "Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Windows Defender Exploit Guard >> Attack Surface Reduction >> \"Configure Attack Surface Reduction rules\" to \"Enabled\". \n\nClick \"Show...\". Set the Value name to \"5BEB7EFE-FD9A-4556-801D-275E5FFC04CC\" and the Value to \"1\".",
"iacontrols": null,
"id": "V-213461",
"ruleID": "SV-213461r823091_rule",
"severity": "medium",
"title": "Microsoft Defender AV must be configured to block execution of potentially obfuscated scripts.",
"version": "WNDF-AV-000037"
},
"V-213462": {
"checkid": "C-14687r820233_chk",
"checktext": "This setting is applicable starting with v1709 of Windows 10. It is NA for prior versions.\n\nVerify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Microsoft Defender Exploit Guard >> Attack Surface Reduction >> \"Configure Attack Surface Reduction rules\" is set to \"Enabled\". Click \"Show...\". Verify the rule ID in the Value name column and the desired state in the Value column is set as follows:\nValue name: 92E97FA1-2EDF-4476-BDD6-9DD0B4DDDC7B\nValue: 1\n\nProcedure: Use the Windows Registry Editor to navigate to the following key: \nHKLM\\Software\\Policies\\Microsoft\\Windows Defender\\Windows Defender Exploit Guard\\ASR\\Rules\n\nCriteria: If the value \"92E97FA1-2EDF-4476-BDD6-9DD0B4DDDC7B\" is REG_SZ = 1, this is not a finding.",
"description": "This rule blocks potentially malicious behavior by not allowing macro code to execute routines in the Win 32 dynamic link library (DLL).",
"fixid": "F-14685r823092_fix",
"fixtext": "Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Windows Defender Exploit Guard >> Attack Surface Reduction >> \"Configure Attack Surface Reduction rules\" to \"Enabled\". \n\nClick \"Show...\". Set the Value name to \"92E97FA1-2EDF-4476-BDD6-9DD0B4DDDC7B\" and the Value to \"1\".",
"iacontrols": null,
"id": "V-213462",
"ruleID": "SV-213462r823093_rule",
"severity": "medium",
"title": "Microsoft Defender AV must be configured to block Win32 imports from macro code in Office.",
"version": "WNDF-AV-000038"
},
"V-213463": {
"checkid": "C-14688r820236_chk",
"checktext": "This setting is applicable starting with v1709 of Windows 10, it is NA for prior versions.\n\nVerify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Microsoft Defender Exploit Guard >> Network Protection >> \"Prevent users and apps from accessing dangerous websites\" is set to \"Enabled\u201d and \"Block\" is selected in the drop-down box.\n\nProcedure: Use the Windows Registry Editor to navigate to the following key: \nHKLM\\Software\\Policies\\Microsoft\\Windows Defender\\Windows Defender Exploit Guard\\Network Protection\n\nCriteria: If the value \"EnableNetworkProtection\" is REG_DWORD = 1, this is not a finding.",
"description": "Enable Microsoft Defender Exploit Guard network protection to prevent employees from using any application to access dangerous domains that may host phishing scams, exploit-hosting sites, and other malicious content on the internet.",
"fixid": "F-14686r823094_fix",
"fixtext": "Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Windows Defender Exploit Guard >> Network Protection >> \"Prevent users and apps from accessing dangerous websites\" to \"Enabled\" and select \"Block\" in the drop-down box.",
"iacontrols": null,
"id": "V-213463",
"ruleID": "SV-213463r823095_rule",
"severity": "medium",
"title": "Microsoft Defender AV must be configured to prevent user and apps from accessing dangerous websites.",
"version": "WNDF-AV-000039"
},
"V-213464": {
"checkid": "C-14689r820239_chk",
"checktext": "Verify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Threats >> \"Specify threat alert levels at which default action should not be taken when detected\" is set to \"Enabled\". \n\nClick the \"Show\u2026\" box option and verify the \"Value name\" field contains a value of \"4\" and the \"Value\" field contains a \"2\". A value of \"3\" in the \"Value\" field is more restrictive and also an acceptable value.\n \nProcedure: Use the Windows Registry Editor to navigate to the following key: \nHKLM\\Software\\Policies\\Microsoft\\Windows Defender\\Threats\\ThreatSeverityDefaultAction\n\nCriteria: If the value \"4\" is REG_SZ = 2 (or 3), this is not a finding.",
"description": "This policy setting allows the customization of which automatic remediation action will be taken for each threat alert level. Threat alert levels should be added under the Options for this setting. Each entry must be listed as a name value pair. The name defines a threat alert level. The value contains the action ID for the remediation action that should be taken. \n\nValid threat alert levels are: \n1 = Low \n2 = Medium \n4 = High \n5 = Severe \n\nValid remediation action values are: \n2 = Quarantine \n3 = Remove \n6 = Ignore",
"fixid": "F-14687r823096_fix",
"fixtext": "Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Threats >> \"Specify threat alert levels at which default action should not be taken when detected\" to \"Enabled\". \n\nSelect the \"Show\u2026\" option box and enter \"4\" in the \"Value name\" field and enter \"2\" in the \"Value\" field.",
"iacontrols": null,
"id": "V-213464",
"ruleID": "SV-213464r823097_rule",
"severity": "medium",
"title": "Microsoft Defender AV must be configured for automatic remediation action to be taken for threat alert level High.",
"version": "WNDF-AV-000040"
},
"V-213465": {
"checkid": "C-14690r820242_chk",
"checktext": "Verify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Threats >> \"Specify threat alert levels at which default action should not be taken when detected\" is set to \"Enabled\". \n\nClick the \"Show\u2026\" box option and verify the \"Value name\" field contains a value of \"2\" and the \"Value\" field contains a \"2\". A value of \"3\" in the \"Value\" field is more restrictive and also an acceptable value.\n \nProcedure: Use the Windows Registry Editor to navigate to the following key: \nHKLM\\Software\\Policies\\Microsoft\\Windows Defender\\Threats\\ThreatSeverityDefaultAction\n\nCriteria: If the value \"2\" is REG_SZ = 2 (or 3), this is not a finding.",
"description": "This policy setting allows the customization of which automatic remediation action will be taken for each threat alert level. Threat alert levels should be added under the Options for this setting. Each entry must be listed as a name value pair. The name defines a threat alert level. The value contains the action ID for the remediation action that should be taken. \n\nValid threat alert levels are: \n1 = Low \n2 = Medium \n4 = High \n5 = Severe \n\nValid remediation action values are: \n2 = Quarantine \n3 = Remove \n6 = Ignore",
"fixid": "F-14688r823098_fix",
"fixtext": "Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Threats >> \"Specify threat alert levels at which default action should not be taken when detected\" to \"Enabled\". \n\nSelect the \"Show\u2026\" option box and enter \"2\" in the \"Value name\" field and enter \"2\" in the \"Value\" field.",
"iacontrols": null,
"id": "V-213465",
"ruleID": "SV-213465r823099_rule",
"severity": "medium",
"title": "Microsoft Defender AV must be configured for automatic remediation action to be taken for threat alert level Medium.",
"version": "WNDF-AV-000041"
},
"V-213466": {
"checkid": "C-14691r820245_chk",
"checktext": "Verify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Threats >> \"Specify threat alert levels at which default action should not be taken when detected\" is set to \"Enabled\". \n\nClick the \"Show\u2026\" box option and verify the \"Value name\" field contains a value of \"1\" and the \"Value\" field contains a \"2\". A value of \"3\" in the \"Value\" field is more restrictive and also an acceptable value.\n \nProcedure: Use the Windows Registry Editor to navigate to the following key: \nHKLM\\Software\\Policies\\Microsoft\\Windows Defender\\Threats\\ThreatSeverityDefaultAction\n\nCriteria: If the value \"1\" is REG_SZ = 2 (or 3), this is not a finding.",
"description": "This policy setting allows the customization of which automatic remediation action will be taken for each threat alert level. Threat alert levels should be added under the Options for this setting. Each entry must be listed as a name value pair. The name defines a threat alert level. The value contains the action ID for the remediation action that should be taken. \n\nValid threat alert levels are: \n1 = Low \n2 = Medium \n4 = High \n5 = Severe \n\nValid remediation action values are: \n2 = Quarantine \n3 = Remove \n6 = Ignore",
"fixid": "F-14689r823100_fix",
"fixtext": "Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Threats >> \"Specify threat alert levels at which default action should not be taken when detected\" to \"Enabled\". \n\nSelect the \"Show\u2026\" option box and enter \"1\" in the \"Value name\" field and enter \"2\" in the \"Value\" field.",
"iacontrols": null,
"id": "V-213466",
"ruleID": "SV-213466r823101_rule",
"severity": "medium",
"title": "Microsoft Defender AV must be configured for automatic remediation action to be taken for threat alert level Low.",
"version": "WNDF-AV-000042"
}
},
"profiles": {
"MAC-1_Classified": {
"description": "",
"findings": {
"V-213426": "true",
"V-213427": "true",
"V-213428": "true",
"V-213429": "true",
"V-213430": "true",
"V-213431": "true",
"V-213432": "true",
"V-213433": "true",
"V-213434": "true",
"V-213435": "true",
"V-213436": "true",
"V-213437": "true",
"V-213438": "true",
"V-213439": "true",
"V-213440": "true",
"V-213441": "true",
"V-213442": "true",
"V-213443": "true",
"V-213444": "true",
"V-213445": "true",
"V-213446": "true",
"V-213447": "true",
"V-213448": "true",
"V-213449": "true",
"V-213450": "true",
"V-213451": "true",
"V-213452": "true",
"V-213453": "true",
"V-213454": "true",
"V-213455": "true",
"V-213456": "true",
"V-213457": "true",
"V-213458": "true",
"V-213459": "true",
"V-213460": "true",
"V-213461": "true",
"V-213462": "true",
"V-213463": "true",
"V-213464": "true",
"V-213465": "true",
"V-213466": "true"
},
"id": "MAC-1_Classified",
"title": "I - Mission Critical Classified"
},
"MAC-1_Public": {
"description": "",
"findings": {
"V-213426": "true",
"V-213427": "true",
"V-213428": "true",
"V-213429": "true",
"V-213430": "true",
"V-213431": "true",
"V-213432": "true",
"V-213433": "true",
"V-213434": "true",
"V-213435": "true",
"V-213436": "true",
"V-213437": "true",
"V-213438": "true",
"V-213439": "true",
"V-213440": "true",
"V-213441": "true",
"V-213442": "true",
"V-213443": "true",
"V-213444": "true",
"V-213445": "true",
"V-213446": "true",
"V-213447": "true",
"V-213448": "true",
"V-213449": "true",
"V-213450": "true",
"V-213451": "true",
"V-213452": "true",
"V-213453": "true",
"V-213454": "true",
"V-213455": "true",
"V-213456": "true",
"V-213457": "true",
"V-213458": "true",
"V-213459": "true",
"V-213460": "true",
"V-213461": "true",
"V-213462": "true",
"V-213463": "true",
"V-213464": "true",
"V-213465": "true",
"V-213466": "true"
},
"id": "MAC-1_Public",
"title": "I - Mission Critical Public"
},
"MAC-1_Sensitive": {
"description": "",
"findings": {
"V-213426": "true",
"V-213427": "true",
"V-213428": "true",
"V-213429": "true",
"V-213430": "true",
"V-213431": "true",
"V-213432": "true",
"V-213433": "true",
"V-213434": "true",
"V-213435": "true",
"V-213436": "true",
"V-213437": "true",
"V-213438": "true",
"V-213439": "true",
"V-213440": "true",
"V-213441": "true",
"V-213442": "true",
"V-213443": "true",
"V-213444": "true",
"V-213445": "true",
"V-213446": "true",
"V-213447": "true",
"V-213448": "true",
"V-213449": "true",
"V-213450": "true",
"V-213451": "true",
"V-213452": "true",
"V-213453": "true",
"V-213454": "true",
"V-213455": "true",
"V-213456": "true",
"V-213457": "true",
"V-213458": "true",
"V-213459": "true",
"V-213460": "true",
"V-213461": "true",
"V-213462": "true",
"V-213463": "true",
"V-213464": "true",
"V-213465": "true",
"V-213466": "true"
},
"id": "MAC-1_Sensitive",
"title": "I - Mission Critical Sensitive"
},
"MAC-2_Classified": {
"description": "",
"findings": {
"V-213426": "true",
"V-213427": "true",
"V-213428": "true",
"V-213429": "true",
"V-213430": "true",
"V-213431": "true",
"V-213432": "true",
"V-213433": "true",
"V-213434": "true",
"V-213435": "true",
"V-213436": "true",
"V-213437": "true",
"V-213438": "true",
"V-213439": "true",
"V-213440": "true",
"V-213441": "true",
"V-213442": "true",
"V-213443": "true",
"V-213444": "true",
"V-213445": "true",
"V-213446": "true",
"V-213447": "true",
"V-213448": "true",
"V-213449": "true",
"V-213450": "true",
"V-213451": "true",
"V-213452": "true",
"V-213453": "true",
"V-213454": "true",
"V-213455": "true",
"V-213456": "true",
"V-213457": "true",
"V-213458": "true",
"V-213459": "true",
"V-213460": "true",
"V-213461": "true",
"V-213462": "true",
"V-213463": "true",
"V-213464": "true",
"V-213465": "true",
"V-213466": "true"
},
"id": "MAC-2_Classified",
"title": "II - Mission Support Classified"
},
"MAC-2_Public": {
"description": "",
"findings": {
"V-213426": "true",
"V-213427": "true",
"V-213428": "true",
"V-213429": "true",
"V-213430": "true",
"V-213431": "true",
"V-213432": "true",
"V-213433": "true",
"V-213434": "true",
"V-213435": "true",
"V-213436": "true",
"V-213437": "true",
"V-213438": "true",
"V-213439": "true",
"V-213440": "true",
"V-213441": "true",
"V-213442": "true",
"V-213443": "true",
"V-213444": "true",
"V-213445": "true",
"V-213446": "true",
"V-213447": "true",
"V-213448": "true",
"V-213449": "true",
"V-213450": "true",
"V-213451": "true",
"V-213452": "true",
"V-213453": "true",
"V-213454": "true",
"V-213455": "true",
"V-213456": "true",
"V-213457": "true",
"V-213458": "true",
"V-213459": "true",
"V-213460": "true",
"V-213461": "true",
"V-213462": "true",
"V-213463": "true",
"V-213464": "true",
"V-213465": "true",
"V-213466": "true"
},
"id": "MAC-2_Public",
"title": "II - Mission Support Public"
},
"MAC-2_Sensitive": {
"description": "",
"findings": {
"V-213426": "true",
"V-213427": "true",
"V-213428": "true",
"V-213429": "true",
"V-213430": "true",
"V-213431": "true",
"V-213432": "true",
"V-213433": "true",
"V-213434": "true",
"V-213435": "true",
"V-213436": "true",
"V-213437": "true",
"V-213438": "true",
"V-213439": "true",
"V-213440": "true",
"V-213441": "true",
"V-213442": "true",
"V-213443": "true",
"V-213444": "true",
"V-213445": "true",
"V-213446": "true",
"V-213447": "true",
"V-213448": "true",
"V-213449": "true",
"V-213450": "true",
"V-213451": "true",
"V-213452": "true",
"V-213453": "true",
"V-213454": "true",
"V-213455": "true",
"V-213456": "true",
"V-213457": "true",
"V-213458": "true",
"V-213459": "true",
"V-213460": "true",
"V-213461": "true",
"V-213462": "true",
"V-213463": "true",
"V-213464": "true",
"V-213465": "true",
"V-213466": "true"
},
"id": "MAC-2_Sensitive",
"title": "II - Mission Support Sensitive"
},
"MAC-3_Classified": {
"description": "",
"findings": {
"V-213426": "true",
"V-213427": "true",
"V-213428": "true",
"V-213429": "true",
"V-213430": "true",
"V-213431": "true",
"V-213432": "true",
"V-213433": "true",
"V-213434": "true",
"V-213435": "true",
"V-213436": "true",
"V-213437": "true",
"V-213438": "true",
"V-213439": "true",
"V-213440": "true",
"V-213441": "true",
"V-213442": "true",
"V-213443": "true",
"V-213444": "true",
"V-213445": "true",
"V-213446": "true",
"V-213447": "true",
"V-213448": "true",
"V-213449": "true",
"V-213450": "true",
"V-213451": "true",
"V-213452": "true",
"V-213453": "true",
"V-213454": "true",
"V-213455": "true",
"V-213456": "true",
"V-213457": "true",
"V-213458": "true",
"V-213459": "true",
"V-213460": "true",
"V-213461": "true",
"V-213462": "true",
"V-213463": "true",
"V-213464": "true",
"V-213465": "true",
"V-213466": "true"
},
"id": "MAC-3_Classified",
"title": "III - Administrative Classified"
},
"MAC-3_Public": {
"description": "",
"findings": {
"V-213426": "true",
"V-213427": "true",
"V-213428": "true",
"V-213429": "true",
"V-213430": "true",
"V-213431": "true",
"V-213432": "true",
"V-213433": "true",
"V-213434": "true",
"V-213435": "true",
"V-213436": "true",
"V-213437": "true",
"V-213438": "true",
"V-213439": "true",
"V-213440": "true",
"V-213441": "true",
"V-213442": "true",
"V-213443": "true",
"V-213444": "true",
"V-213445": "true",
"V-213446": "true",
"V-213447": "true",
"V-213448": "true",
"V-213449": "true",
"V-213450": "true",
"V-213451": "true",
"V-213452": "true",
"V-213453": "true",
"V-213454": "true",
"V-213455": "true",
"V-213456": "true",
"V-213457": "true",
"V-213458": "true",
"V-213459": "true",
"V-213460": "true",
"V-213461": "true",
"V-213462": "true",
"V-213463": "true",
"V-213464": "true",
"V-213465": "true",
"V-213466": "true"
},
"id": "MAC-3_Public",
"title": "III - Administrative Public"
},
"MAC-3_Sensitive": {
"description": "",
"findings": {
"V-213426": "true",
"V-213427": "true",
"V-213428": "true",
"V-213429": "true",
"V-213430": "true",
"V-213431": "true",
"V-213432": "true",
"V-213433": "true",
"V-213434": "true",
"V-213435": "true",
"V-213436": "true",
"V-213437": "true",
"V-213438": "true",
"V-213439": "true",
"V-213440": "true",
"V-213441": "true",
"V-213442": "true",
"V-213443": "true",
"V-213444": "true",
"V-213445": "true",
"V-213446": "true",
"V-213447": "true",
"V-213448": "true",
"V-213449": "true",
"V-213450": "true",
"V-213451": "true",
"V-213452": "true",
"V-213453": "true",
"V-213454": "true",
"V-213455": "true",
"V-213456": "true",
"V-213457": "true",
"V-213458": "true",
"V-213459": "true",
"V-213460": "true",
"V-213461": "true",
"V-213462": "true",
"V-213463": "true",
"V-213464": "true",
"V-213465": "true",
"V-213466": "true"
},
"id": "MAC-3_Sensitive",
"title": "III - Administrative Sensitive"
}
},
"slug": "microsoft_defender_antivirus",
"title": "Microsoft Defender Antivirus Security Technical Implementation Guide",
"version": "2"
}
}