move ASR rule descriptions to make the flow more logical

This commit is contained in:
Iaan D'Souza-Wiltshire
2017-08-28 13:17:17 -07:00
parent 44a575f80e
commit 11e92ab396
3 changed files with 75 additions and 7 deletions

View File

@ -80,9 +80,9 @@ You can review the Windows event log to see events that are created when Exploit
4. Navigate to where you extracted *ep-events.xml* and select it. Alternatively, [copy the XML directly](event-views-exploit-guard.md).
4. Click **OK**.
5. Click **OK**.
5. This will create a custom view that filters to only show the following events related to Controlled Folder Access:
6. This will create a custom view that filters to only show the following events related to Exploit Protection:
Provider/source | Event ID | Description
-|:-:|-