Microsoft Defender for Endpoint
Endpoint protection

Tamper Resiliency

In brief

Updated links now point to revised Zero Trust, Group Policy, WDAC, and vulnerable driver block-list documentation locations.

What Defender admins need to know

Administrators should use the revised links when following the tamper-resiliency guidance.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Organization wide tamper resiliency is built on Zero Trust

The foundation for defending against tampering is following a Zero TrustZero Trust model.

You can view health status for Microsoft Defender Antivirus health and sensors in the device health reports in Microsoft Defender for Endpoint.

| Tamper protection | Windows | - Terminating/suspending processes
- Stopping/pausing/suspending services
- Modifying registry settings including exclusions
- Manipulating/hijacking DLLs
- Manipulation/modification of the file system
- Agent integrity | | Tamper protection | Mac | - Terminating/suspending processes
- Manipulation/modification of the file system
- Agent integrity| | Attack surface reduction (ASR) rules | Windows | Kernel drivers (see Block abuse of exploited vulnerable signed drivers (Device))| | Windows Defender Application ControlWindows Defender Application Control (WDAC) | Windows | Kernel drivers (see Microsoft vulnerable driver block listMicrosoft vulnerable driver block list)|

Understanding the different ways to prevent driver based tampering on Windows

The block list is updated with each new major release of Windows, typically 1-2 times per year. Microsoft will occasionally publish future updates through regular Windows servicing. With Windows 11 2022 update, the vulnerable driver block list is enabled by default for all devices, but requires either memory integrity (also known as hypervisor-protected code integrity or HVCI), Smart App Control, or S mode to be active.

See Microsoft vulnerable driver block listMicrosoft vulnerable driver block list.

For devices that don't meet those requirements, this list of drivers can be blocked by using Windows Defender Application Control policy.

See Vulnerable Driver block list XMLVulnerable Driver block list XML.

Faster updates - Block exploited vulnerable and signed drivers ASR rule

Block other drivers - Windows Defender Application Control (WDAC)

Attackers might attempt to use drivers that aren't blocked by either the recommended driver block list or an ASR rule. In this case, customers can protect themselves by using WDAC to create a policy to blockWDAC to create a policy to block

WDAC also provides an audit mode to help understand the impact of applying the policy in block mode to avoid accidentally impacting legitimate use.

If the Block abuse of exploited vulnerable signed drivers (Device) attack surface reduction rule is triggered, the event is viewable in the ASR Report and in Advanced Hunting.

If Windows Defender Application ControlWindows Defender Application Control (WDAC) is enabled, the block and audit activity can be seen in Advanced Huntingblock and audit activity can be seen in Advanced Hunting.