Nov 02 2021 04:50 PM
Hello ,
I am using the following query to get the statistics on ASR rules on a host and their status:
Nov 03 2021 03:11 AM
Solution@Princely Just to confirm that the only AV active\installed is Defender? if not then ASR rules do not work\report correctly. Also worth testing https://demo.wd.microsoft.com/ to check for detections (allow 10-15mins). Some rules just generate nothing until triggered which could take a while before this happens things Folder protection or meets prevalence rules will generate more results quicker.
Nov 03 2021 04:57 AM
Nov 30 2021 06:13 PM
Nov 03 2021 03:11 AM
Solution@Princely Just to confirm that the only AV active\installed is Defender? if not then ASR rules do not work\report correctly. Also worth testing https://demo.wd.microsoft.com/ to check for detections (allow 10-15mins). Some rules just generate nothing until triggered which could take a while before this happens things Folder protection or meets prevalence rules will generate more results quicker.