Forum Discussion

Hnqeee's avatar
Hnqeee
Occasional Reader
Sep 23, 2025

ADR: Audited detections not showing in Microsoft Defender

Hi all,

I am trying to figure out why the Attack surface reduction rules report does not show me any audited detections. Specifically, I am testing out the rule Block process creations originating from PSExec and WMI commands in Audit mode. A test was run on the endpoint by starting a WMI process and an event was logged to Event Viewer → Applications and Services Logs → Microsoft → Windows → Windows Defender → Operational. 

Any ideas?

No RepliesBe the first to reply

Resources