MS Windows Defender Antivirus Security Technical Implementation Guide

The Windows Defender Antivirus Security Technical Implementation Guide (STIG) is published as a tool to improve the security of Department of Defense (DoD) information systems. Comments or proposed revisions to this document should be send via e-mail to the following address: [email protected]

Details

Version / Release: V1R8

Published: 2020-03-19

Updated At: 2020-05-11 21:06:20

Compare/View Releases

Select any two versions of this STIG to compare the individual requirements

Select any old version/release of this STIG to view the previous requirements

Actions

Download

Filter


Findings
Severity Open Not Reviewed Not Applicable Not a Finding
Overall 0 0 0 0
Low 0 0 0 0
Medium 0 0 0 0
High 0 0 0 0
Drop CKL or SCAP (XCCDF) results here.

    Vuln Rule Version CCI Severity Title Description Status Finding Details Comments
    SV-89827r3_rule WNDF-AV-000001 CCI-001243 HIGH Windows Defender AV must be configured to block the Potentially Unwanted Application (PUA) feature. After enabling this feature, PUA protection blocking takes effect on endpoint clients after the next signature update or computer restart. Signature updates take place daily under typical circumstances. PUA will be blocked and automatically quarantined.
    SV-89831r2_rule WNDF-AV-000003 CCI-001243 MEDIUM Windows Defender AV must be configured to automatically take action on all detected tasks. This policy setting allows you to configure whether Windows Defender automatically takes action on all detected threats. The action to be taken on a particular threat is determined by the combination of the policy-defined action user-defined action and th
    SV-89833r5_rule WNDF-AV-000004 CCI-001242 HIGH Windows Defender AV must be configured to run and scan for malware and other potentially unwanted software. This policy setting turns off Windows Defender Antivirus. If you enable this policy setting Windows Defender Antivirus does not run and computers are not scanned for malware or other potentially unwanted software. When the setting is Disabled and a third-
    SV-89835r2_rule WNDF-AV-000005 CCI-001242 MEDIUM Windows Defender AV must be configured to not exclude files for scanning. This policy setting allows you to disable scheduled and real-time scanning for files under the paths specified or for the fully qualified resources specified. Paths should be added under the Options for this setting. Each entry must be listed as a name va
    SV-89837r2_rule WNDF-AV-000006 CCI-001242 MEDIUM Windows Defender AV must be configured to not exclude files opened by specified processes. This policy setting allows you to disable scheduled and real-time scanning for any file opened by any of the specified processes. The process itself will not be excluded. To exclude the process use the Path exclusion. Processes should be added under the O
    SV-89839r2_rule WNDF-AV-000007 CCI-001242 MEDIUM Windows Defender AV must be configured to enable the Automatic Exclusions feature. Allows an administrator to specify if Automatic Exclusions feature for Server SKUs should be turned off.
    SV-89841r2_rule WNDF-AV-000008 CCI-001170 MEDIUM Windows Defender AV must be configured to disable local setting override for reporting to Microsoft MAPS. This policy setting configures a local override for the configuration to join Microsoft MAPS. This setting can only be set by Group Policy. If you enable this setting the local preference setting will take priority over Group Policy. If you disable or do
    SV-89843r2_rule WNDF-AV-000009 CCI-001242 MEDIUM Windows Defender AV must be configured to check in real time with MAPS before content is run or accessed. This feature ensures the device checks in real time with the Microsoft Active Protection Service (MAPS) before allowing certain content to be run or accessed. If this feature is disabled the check will not occur which will lower the protection state of th
    SV-89847r6_rule WNDF-AV-000010 CCI-001170 MEDIUM Windows Defender AV must be configured to join Microsoft MAPS. This policy setting allows you to join Microsoft MAPS. Microsoft MAPS is the online community that helps you choose how to respond to potential threats. The community also helps stop the spread of new malicious software infections. You can choose to send
    SV-89887r3_rule WNDF-AV-000011 CCI-001170 MEDIUM Windows Defender AV must be configured to only send safe samples for MAPS telemetry. This policy setting configures behavior of samples submission when opt-in for MAPS telemetry is set. Possible options are: (0x0) Always prompt (0x1) Send safe samples automatically (0x2) Never send (0x3) Send all samples automatically.
    SV-89889r2_rule WNDF-AV-000012 CCI-001242 MEDIUM Windows Defender AV must be configured for protocol recognition for network protection. This policy setting allows you to configure protocol recognition for network protection against exploits of known vulnerabilities. If you enable or do not configure this setting protocol recognition will be enabled. If you disable this setting protocol re
    SV-89891r2_rule WNDF-AV-000013 CCI-001695 MEDIUM Windows Defender AV must be configured to not allow local override of monitoring for file and program activity. This policy setting configures a local override for the configuration of monitoring for file and program activity on your computer. This setting can only be set by Group Policy. If you enable this setting the local preference setting will take priority ov
    SV-89893r2_rule WNDF-AV-000014 CCI-001695 MEDIUM Windows Defender AV must be configured to not allow override of monitoring for incoming and outgoing file activity. This policy setting configures a local override for the configuration of monitoring for incoming and outgoing file activity. This setting can only be set by Group Policy. If you enable this setting the local preference setting will take priority over Grou
    SV-89895r2_rule WNDF-AV-000015 CCI-001169 MEDIUM Windows Defender AV must be configured to not allow override of scanning for downloaded files and attachments. This policy setting configures a local override for the configuration of scanning for all downloaded files and attachments. This setting can only be set by Group Policy. If you enable this setting the local preference setting will take priority over Group
    SV-89897r2_rule WNDF-AV-000016 CCI-001170 MEDIUM Windows Defender AV must be configured to not allow override of behavior monitoring. This policy setting configures a local override for the configuration of behavior monitoring. This setting can only be set by Group Policy. If you enable this setting the local preference setting will take priority over Group Policy. If you disable or do
    SV-89899r2_rule WNDF-AV-000017 CCI-001242 MEDIUM Windows Defender AV Group Policy settings must take priority over the local preference settings. This policy setting configures a local override for the configuration to turn on real-time protection. This setting can only be set by Group Policy. If you enable this setting the local preference setting will take priority over Group Policy. If you disab
    SV-89901r2_rule WNDF-AV-000018 CCI-001242 MEDIUM Windows Defender AV must monitor for incoming and outgoing files. This policy setting allows you to configure monitoring for incoming and outgoing files without having to turn off monitoring entirely. It is recommended for use on servers where there is a lot of incoming and outgoing file activity but for performance rea
    SV-89903r2_rule WNDF-AV-000019 CCI-001242 MEDIUM Windows Defender AV must be configured to monitor for file and program activity. This policy setting allows you to configure monitoring for file and program activity. If you enable or do not configure this setting monitoring for file and program activity will be enabled. If you disable this setting monitoring for file and program acti
    SV-89905r2_rule WNDF-AV-000020 CCI-001169 MEDIUM Windows Defender AV must be configured to scan all downloaded files and attachments. This policy setting allows you to configure scanning for all downloaded files and attachments. If you enable or do not configure this setting scanning for all downloaded files and attachments will be enabled. If you disable this setting scanning for all d
    SV-89907r2_rule WNDF-AV-000021 CCI-001242 MEDIUM Windows Defender AV must be configured to always enable real-time protection. This policy setting turns off real-time protection prompts for known malware detection. Windows Defender Antivirus alerts you when malware or potentially unwanted software attempts to install itself or to run on your computer. If you enable this policy se
    SV-89909r2_rule WNDF-AV-000022 CCI-001170 MEDIUM Windows Defender AV must be configured to enable behavior monitoring. This policy setting allows you to configure behavior monitoring. If you enable or do not configure this setting behavior monitoring will be enabled. If you disable this setting behavior monitoring will be disabled.
    SV-89911r2_rule WNDF-AV-000023 CCI-001242 MEDIUM Windows Defender AV must be configured to process scanning when real-time protection is enabled. This policy setting allows you to configure process scanning when real-time protection is turned on. This helps to catch malware which could start when real-time protection is turned off. If you enable or do not configure this setting a process scan will
    SV-89913r2_rule WNDF-AV-000024 CCI-001242 MEDIUM Windows Defender AV must be configured to scan archive files. This policy setting allows you to configure scans for malicious software and unwanted software in archive files such as .ZIP or .CAB files. If you enable or do not configure this setting archive files will be scanned. If you disable this setting archive f
    SV-89915r2_rule WNDF-AV-000025 CCI-000870 MEDIUM Windows Defender AV must be configured to scan removable drives. This policy setting allows you to manage whether or not to scan for malicious software and unwanted software in the contents of removable drives such as USB flash drives when running a full scan. If you enable this setting removable drives will be scanned
    SV-89917r2_rule WNDF-AV-000026 CCI-001241 MEDIUM Windows Defender AV must be configured to perform a weekly scheduled scan. This policy setting allows you to specify the day of the week on which to perform a scheduled scan. The scan can also be configured to run every day or to never run at all. This setting can be configured with the following ordinal number values: (0x0) Eve
    SV-89919r2_rule WNDF-AV-000027 CCI-001170 MEDIUM Windows Defender AV must be configured to turn on e-mail scanning. This policy setting allows you to configure e-mail scanning. When e-mail scanning is enabled the engine will parse the mailbox and mail files according to their specific format in order to analyze the mail bodies and attachments. Several e-mail formats ar
    SV-89921r2_rule WNDF-AV-000028 CCI-001240 HIGH Windows Defender AV spyware definition age must not exceed 7 days. This policy setting allows you to define the number of days that must pass before spyware definitions are considered out of date. If definitions are determined to be out of date this state may trigger several additional actions including falling back to a
    SV-89923r2_rule WNDF-AV-000029 CCI-001240 HIGH Windows Defender AV virus definition age must not exceed 7 days. This policy setting allows you to define the number of days that must pass before virus definitions are considered out of date. If definitions are determined to be out of date this state may trigger several additional actions including falling back to an
    SV-89925r2_rule WNDF-AV-000030 CCI-001308 MEDIUM Windows Defender AV must be configured to check for definition updates daily. This policy setting allows you to specify the day of the week on which to check for definition updates. The check can also be configured to run every day or to never run at all. This setting can be configured with the following ordinal number values: (0x0
    SV-89927r3_rule WNDF-AV-000031 CCI-001662 MEDIUM Windows Defender AV must be configured for automatic remediation action to be taken for threat alert level Severe. This policy setting allows you to customize which automatic remediation action will be taken for each threat alert level. Threat alert levels should be added under the Options for this setting. Each entry must be listed as a name value pair. The name defi
    SV-92661r1_rule WNDF-AV-000032 CCI-001170 MEDIUM Windows Defender AV must be configured to block executable content from email client and webmail. This rule blocks the following file types from being run or launched from an email seen in either Microsoft Outlook or webmail (such as Gmail.com or Outlook.com): Executable files (such as .exe, .dll, or .scr) Script files (such as a PowerShell .ps, Visua
    SV-92663r1_rule WNDF-AV-000033 CCI-001170 MEDIUM Windows Defender AV must be configured block Office applications from creating child processes. Office apps, such as Word or Excel, will not be allowed to create child processes. This is a typical malware behavior, especially for macro-based attacks that attempt to use Office apps to launch or download malicious executables.
    SV-92665r1_rule WNDF-AV-000034 CCI-001170 MEDIUM Windows Defender AV must be configured block Office applications from creating executable content. This rule targets typical behaviors used by suspicious and malicious add-ons and scripts (extensions) that create or launch executable files. This is a typical malware technique. Extensions will be blocked from being used by Office apps. Typically these e
    SV-92667r1_rule WNDF-AV-000035 CCI-001170 MEDIUM Windows Defender AV must be configured to block Office applications from injecting into other processes. Office apps, such as Word, Excel, or PowerPoint, will not be able to inject code into other processes. This is typically used by malware to run malicious code in an attempt to hide the activity from antivirus scanning engines.
    SV-92669r1_rule WNDF-AV-000036 CCI-001170 MEDIUM Windows Defender AV must be configured to impede JavaScript and VBScript to launch executables. JavaScript and VBScript scripts can be used by malware to launch other malicious apps. This rule prevents these scripts from being allowed to launch apps, thus preventing malicious use of the scripts to spread malware and infect machines.
    SV-92671r1_rule WNDF-AV-000037 CCI-001170 MEDIUM Windows Defender AV must be configured to block execution of potentially obfuscated scripts. Malware and other threats can attempt to obfuscate or hide their malicious code in some script files. This rule prevents scripts that appear to be obfuscated from running. It uses the AntiMalwareScanInterface (AMSI) to determine if a script is potentiall
    SV-92673r1_rule WNDF-AV-000038 CCI-001170 MEDIUM Windows Defender AV must be configured to block Win32 imports from macro code in Office. This rule blocks potentially malicious behavior by not allowing macro code to execute routines in the Win 32 dynamic link library (DLL).
    SV-92675r1_rule WNDF-AV-000039 CCI-001170 MEDIUM Windows Defender AV must be configured to prevent user and apps from accessing dangerous websites. Enable Windows Defender Exploit Guard network protection to prevent employees from using any application to access dangerous domains that may host phishing scams exploit-hosting sites and other malicious content on the Internet.
    SV-94669r1_rule WNDF-AV-000040 CCI-001662 MEDIUM Windows Defender AV must be configured for automatic remediation action to be taken for threat alert level High. This policy setting allows you to customize which automatic remediation action will be taken for each threat alert level. Threat alert levels should be added under the Options for this setting. Each entry must be listed as a name value pair. The name defi
    SV-94671r1_rule WNDF-AV-000041 CCI-001662 MEDIUM Windows Defender AV must be configured for automatic remediation action to be taken for threat alert level Medium. This policy setting allows you to customize which automatic remediation action will be taken for each threat alert level. Threat alert levels should be added under the Options for this setting. Each entry must be listed as a name value pair. The name defi
    SV-94675r1_rule WNDF-AV-000042 CCI-001662 MEDIUM Windows Defender AV must be configured for automatic remediation action to be taken for threat alert level Low. This policy setting allows you to customize which automatic remediation action will be taken for each threat alert level. Threat alert levels should be added under the Options for this setting. Each entry must be listed as a name value pair. The name defi