mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-06-24 06:43:38 +00:00
final changes/tweaks to check meta before pub
This commit is contained in:
@ -11,7 +11,7 @@ ms.pagetype: security
|
||||
localizationpriority: medium
|
||||
author: iaanw
|
||||
ms.author: iawilt
|
||||
ms.date:08/25/2017
|
||||
ms.date: 08/25/2017
|
||||
---
|
||||
|
||||
|
||||
@ -66,7 +66,7 @@ Insider Preview build 16232 or later (dated July 1, 2017 or later) | [Windows De
|
||||
|
||||
## Review Attack Surface Reduction events in Windows Event Viewer
|
||||
|
||||
You can review the Windows event log to see events there are created when an Attack Surface Reduction rule is triggered:
|
||||
You can review the Windows event log to see events that are created when an Attack Surface Reduction rule is triggered (or audited):
|
||||
|
||||
1. Download the [Exploit Guard Evaluation Package](#) and extract the file *asr-events.xml* to an easily accessible location on the machine.
|
||||
|
||||
@ -74,6 +74,8 @@ You can review the Windows event log to see events there are created when an Att
|
||||
|
||||
2. On the left panel, under **Actions**, click **Import custom view...**
|
||||
|
||||

|
||||
|
||||
3. Navigate to the Exploit Guard Evaluation Package, and select the file *asr-events.xml*. Alternatively, [copy the XML directly](event-views-exploit-guard.md).
|
||||
|
||||
4. Click **OK**.
|
||||
|
Reference in New Issue
Block a user