Microsoft Defender for Endpoint
Vulnerabilities and exposure

Attack Surface Reduction Rules Reference

In brief

Three ASR rule entries now use relative links to the cloud-delivered protection documentation.

What Defender admins need to know

Administrators following ASR rule guidance can use the updated links to review the cloud-delivered protection prerequisite.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Block JavaScript or VBScript from launching downloaded executable content

This ASR rule provides an extra layer of protection against ransomware. It uses both client and cloud heuristics to determine whether a file resembles ransomware. This rule doesn't block files that have one or more of the following characteristics: