asr changes

This commit is contained in:
Iaan D'Souza-Wiltshire 2017-08-15 18:59:56 -07:00
parent f594ecf3f5
commit 396ae19f2e
2 changed files with 2 additions and 4 deletions

View File

@ -108,8 +108,6 @@ See the [Evaluate Attack Surface Reduction rules](evaluate-attack-surface-reduct
>[!NOTE]
>Not sure if this is right. What does AttackSurfaceReductionRules_Actions do? Do you need to add $TRUE/$FALSE or 1/0 at the end to enable it? Does the rule need to go in " or {}? Some examples would be handy here I think
>[!IMPORTANT]
>Use `Add-MpPreference` to append or add rules. Using the `Set-MpPreference` cmdlet will overwrite the existing list.
You can enable the feauting in auditing mode using the following cmdlet:
@ -117,7 +115,7 @@ You can enable the feauting in auditing mode using the following cmdlet:
Set-MpPreference -AttackSurfaceReductionRules_Actions AuditMode
```
Use `Disabled` insead of AuditMode to turn the feature off.
Use `Disabled` insead of `AuditMode` or `Enabled` to turn the feature off.
>[!NOTE]
>We need to walk through this so I understand how it works

View File

@ -222,7 +222,7 @@ You can also review the Windows event log to see the events there were created w
5. This will create a custom view that filters to only show the following events related to Attack Surface Reduction:
Event ID | Description
Event ID | Description
-|-
5007 | Event when settings are changed
1122 | Event when rule fires in Audit-mode