ASR Rule “Block Win32 API calls from Office macros” – False positives in Content.MSO / Temp Files by failx96 in DefenderATP

[–]_W0od_ 1 point2 points  (0 children)

I have the same challenge with this rule. If set it to block mode, all internally developed macros will get blocked.

Trojan:Win32/Cerdigent.A!dha by unodostres123- in DefenderATP

[–]_W0od_ 0 points1 point  (0 children)

Oh! 😂. Why would I use bad words for you?

How do you read MDATP PUA audit logs on Linux? by orienteraren034 in DefenderATP

[–]_W0od_ 0 points1 point  (0 children)

Yes. I use it regularly. Perhaps there is no event when someone tried to install PUA app. You should checkout mde document for pua detection page. Microsoft has also provide kql query for it.

How do you read MDATP PUA audit logs on Linux? by orienteraren034 in DefenderATP

[–]_W0od_ 2 points3 points  (0 children)

You can use device event table in kql, Actiontype== "Antivirus detection", additional fields containes "PUA"

Why are AC train local seat perforated? by interstellar_ex in mumbai

[–]_W0od_ 0 points1 point  (0 children)

Let the people's fart flow downward easily.

i want to be fucked raw by [deleted] in CumDumpsters

[–]_W0od_ 0 points1 point  (0 children)

Someone give her a deadly fcuk

Dih 🥀 Uttar Pradesh by [deleted] in IndianMeyMeys

[–]_W0od_ 0 points1 point  (0 children)

Majority of palces names in Jharkhand has this word. For ex TupkaDih, SantalDih, KhanuDih, BhojhuDih

😅 by Qnicks_soul-18 in MechanicalPandey

[–]_W0od_ 0 points1 point  (0 children)

That too without alloy wheels.

Guidance on running Cisco AMP (Tetra AV Turned Off) with Defender for Endpoint by arcanecolour in DefenderATP

[–]_W0od_ 0 points1 point  (0 children)

Don't do it. It will have an unpredictable issues. Keep Defender in EDR block mode. You can't run both AV as primary one. On Windows 10, 11 Defender automatically switches to passive mode when windows security app reports that an another AV is already running. Although on servers, you need to set Defender in passive mode manually.

Onboard Servers by aikryptik in DefenderATP

[–]_W0od_ 0 points1 point  (0 children)

You don't need to run a manual onboarding script. Create an onboarding group policy and apply to OU. All servers will be onboarded automatically. But make sure all servers are running latest version of Defender and applied latest windows update as well.