STIGQter STIGQter: STIG Summary: Microsoft Windows Defender Antivirus Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 04 May 2021:

Windows Defender AV must be configured to only send safe samples for MAPS telemetry.

DISA Rule

SV-213435r569189_rule

Vulnerability Number

V-213435

Group Title

SRG-APP-000210

Rule Version

WNDF-AV-000011

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

This is applicable to unclassified systems, for other systems this is NA.

Set the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Windows Defender Antivirus -> MAPS -> "Send file samples when further analysis is required" to "Enabled" and select "Send safe samples" from the drop down box.

Check Contents

This is applicable to unclassified systems, for other systems this is NA.

Verify the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Windows Defender Antivirus -> MAPS -> "Send file samples when further analysis is required" is set to "Enabled" and "Send safe samples" selected from the drop down box.

Procedure: Use the Windows Registry Editor to navigate to the following key:
HKLM\Software\Policies\Microsoft\Windows Defender\Spynet

Criteria: If the value "SubmitSamplesConsent" is REG_DWORD = 1, this is not a finding.

Vulnerability Number

V-213435

Documentable

False

Rule Version

WNDF-AV-000011

Severity Override Guidance

This is applicable to unclassified systems, for other systems this is NA.

Verify the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Windows Defender Antivirus -> MAPS -> "Send file samples when further analysis is required" is set to "Enabled" and "Send safe samples" selected from the drop down box.

Procedure: Use the Windows Registry Editor to navigate to the following key:
HKLM\Software\Policies\Microsoft\Windows Defender\Spynet

Criteria: If the value "SubmitSamplesConsent" is REG_DWORD = 1, this is not a finding.

Check Content Reference

M

Target Key

3985

Comments