Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Tampering describes attempts by attackers to weaken Microsoft Defender for Endpoint. Attackers might target security controls on individual devices as part of a larger objective, such as deploying ransomware. Tamper resiliency combines device-level protections, centralized management, and detection to help prevent these changes and reduce their impact.
For tamper protection modes, protected settings, requirements, exclusions, and investigation guidance, see Protect security settings with tamper protection.
Build organization-wide tamper resiliency on a Zero Trust model:
- Follow the best practice of least privilege. See Access control overview for Windows.
- Configure Conditional Access policies to apply access controls based on user and device signals.
Keep devices healthy and centrally managed:
- Onboard devices to Defender for Endpoint.
- Make sure security intelligence and antivirus updates are installed.
- Manage devices centrally by using Microsoft Intune, Microsoft Defender for Endpoint security settings management, or Configuration Manager.
Note
On Windows devices, you can manage Microsoft Defender Antivirus by using Group Policy, Windows Management Instrumentation (WMI), and PowerShell cmdlets. These methods are more susceptible to tampering than centralized management through Intune, Configuration Manager, or Defender for Endpoint security settings management.
If you're using Group Policy, we recommend disabling local overrides for Microsoft Defender Antivirus settings and disabling local list merging.
Use the device health reports in Microsoft Defender for Endpoint to review the health of Microsoft Defender Antivirus and Defender for Endpoint sensors.
Prevent tampering on individual devices
Different controls protect against different tampering techniques:
| Control | Platform | Tampering techniques |
|---|---|---|
| Tamper protection | Windows | Terminate or suspend processes, stop services, modify registry settings or exclusions, hijack DLLs, modify the file system, or impair agent integrity. |
| Tamper protection | macOS | Terminate or suspend processes, modify Defender for Endpoint files, or impair agent integrity. |
| Attack surface reduction (ASR) rules | Windows | Prevent apps from writing exploited vulnerable signed drivers to disk. See Block abuse of exploited vulnerable signed drivers (Device). |
| App Control for Business, formerly Windows Defender Application Control (WDAC) | Windows | Prevent vulnerable kernel drivers from loading. See Microsoft vulnerable driver block list. |
Protect against driver-based tampering on Windows
Attackers can exploit vulnerabilities in signed drivers to gain kernel access and disable or bypass security controls. Use the Microsoft vulnerable driver blocklist, an ASR rule, and App Control for Business policies to reduce this risk.
Use the Microsoft vulnerable driver blocklist
Since the Windows 11 2022 Update, the vulnerable driver blocklist is enabled by default. Except on Windows Server 2016, the blocklist is also enforced when memory integrity, also known as hypervisor-protected code integrity (HVCI), Smart App Control, or S mode is active. The blocklist is updated quarterly, and updates are delivered through monthly Windows updates.
See Microsoft vulnerable driver block list.
To deploy the latest recommended blocklist through an App Control for Business policy, see Vulnerable driver blocklist XML.
Use the vulnerable signed drivers ASR rule
The Block abuse of exploited vulnerable signed drivers ASR rule prevents apps from saving vulnerable signed drivers on a device. It doesn't prevent an existing driver from loading. Run the rule in Audit mode to evaluate its effect before you use Block mode. For more information, see Block abuse of exploited vulnerable signed drivers (Device).
Use App Control for Business to block drivers
App Control for Business operational guidance explains how to create policies that control which drivers can run. Use audit mode to evaluate compatibility before you enforce an App Control policy.
Protect Microsoft Defender Antivirus exclusions on Windows
Attackers might add or modify Microsoft Defender Antivirus exclusions to avoid scanning. Tamper protection can protect organization-managed exclusion lists when devices meet the platform, management, sensor, and policy requirements. For the complete requirements and verification steps, see Protect Microsoft Defender Antivirus exclusions with tamper protection.
The DisableLocalAdminMerge setting is one of the exclusion-protection requirements. For configuration information, see Disable local list merging.
As a separate protection, enable HideExclusionsFromLocalAdmin to prevent local administrators from viewing existing exclusions through Registry Editor or the Get-MpPreference PowerShell cmdlet. This setting doesn't remove the exclusions.
Detecting potential tampering activity in the Microsoft Defender portal
Some potential tampering activity generates an alert in the Microsoft Defender portal. To reduce unnecessary alert noise, activity that isn't correlated with suspicious behavior might not generate a standalone alert. The activity remains available in the device timeline and advanced hunting. For investigation guidance, see View information about tampering attempts.
Tampering alert titles can include:
- Attempt to bypass Microsoft Defender for Endpoint client protection
- Attempt to stop Microsoft Defender for Endpoint sensor
- Attempt to tamper with Microsoft Defender on multiple devices
- Attempt to turn off Microsoft Defender Antivirus protection
- Defender detection bypass
- Driver-based tampering attempt blocked
- Image file execution options set for tampering purposes
- Microsoft Defender Antivirus protection turned off
- Microsoft Defender Antivirus tampering
- Modification attempt in Microsoft Defender Antivirus exclusion list
- Pending file operations mechanism abused for tampering purposes
- Possible anti-malware Scan Interface (AMSI) tampering
- Possible remote tampering
- Possible sensor tampering in memory
- Potential attempt to tamper with MDE via drivers
- Security software tampering
- Suspicious Microsoft Defender Antivirus exclusion
- Tamper protection bypass
- Tampering activity typical to ransomware attacks
- Tampering with Microsoft Defender for Endpoint sensor communication
- Tampering with Microsoft Defender for Endpoint sensor settings
- Tampering with the Microsoft Defender for Endpoint sensor
If the Block abuse of exploited vulnerable signed drivers (Device) ASR rule is triggered, view the event in the attack surface reduction rules report or advanced hunting.
If App Control for Business is enabled, you can view block and audit activity in advanced hunting.