STIGQter STIGQter: STIG Summary:

Microsoft Defender Antivirus Security Technical Implementation Guide

Version: 2

Release: 9 Benchmark Date: 01 Jul 2026

CheckedNameTitle
☐SV-213426r961197_ruleMicrosoft Defender AV must be configured to block the Potentially Unwanted Application (PUA) feature.
☐SV-213427r961197_ruleMicrosoft Defender AV must be configured to automatically take action on all detected tasks.
☐SV-213428r1192794_ruleMicrosoft Defender AV must be configured to run and scan for malware and other potentially unwanted software.
☐SV-213429r1207390_ruleMicrosoft Defender AV must be configured to not exclude files for scanning.
☐SV-213430r1207392_ruleMicrosoft Defender AV must be configured to not exclude files opened by specified processes.
☐SV-213431r1207394_ruleMicrosoft Defender AV must be configured to enable the Automatic Exclusions feature.
☐SV-213432r961092_ruleMicrosoft Defender AV must be configured to disable local setting override for reporting to Microsoft MAPS.
☐SV-213433r1192798_ruleMicrosoft Defender AV must be configured to check in real time with MAPS before content is run or accessed.
☐SV-213434r1134051_ruleMicrosoft Defender AV must join Microsoft MAPS.
☐SV-213435r961092_ruleMicrosoft Defender AV must be configured to only send safe samples for MAPS telemetry.
☐SV-213436r1192799_ruleMicrosoft Defender AV must be configured for protocol recognition for network protection.
☐SV-213437r960921_ruleMicrosoft Defender AV must be configured to not allow local override of monitoring for file and program activity.
☐SV-213438r960921_ruleMicrosoft Defender AV must be configured to not allow override of monitoring for incoming and outgoing file activity.
☐SV-213439r961089_ruleMicrosoft Defender AV must be configured to not allow override of scanning for downloaded files and attachments.
☐SV-213440r961092_ruleMicrosoft Defender AV must be configured to not allow override of behavior monitoring.
☐SV-213441r1192800_ruleMicrosoft Defender AV Group Policy settings must take priority over the local preference settings.
☐SV-213442r1192801_ruleMicrosoft Defender AV must monitor for incoming and outgoing files.
☐SV-213443r1192802_ruleMicrosoft Defender AV must be configured to monitor for file and program activity.
☐SV-213444r961089_ruleMicrosoft Defender AV must be configured to scan all downloaded files and attachments.
☐SV-213445r1192803_ruleMicrosoft Defender AV must be configured to always enable real-time protection.
☐SV-213446r961092_ruleMicrosoft Defender AV must be configured to enable behavior monitoring.
☐SV-213447r1192804_ruleMicrosoft Defender AV must be configured to process scanning when real-time protection is enabled.
☐SV-213448r1192805_ruleMicrosoft Defender AV must be configured to scan archive files.
☐SV-213449r960852_ruleMicrosoft Defender AV must be configured to scan removable drives.
☐SV-213450r961191_ruleMicrosoft Defender AV must be configured to perform a weekly scheduled scan.
☐SV-213451r961092_ruleMicrosoft Defender AV must be configured to turn on e-mail scanning.
☐SV-213452r1192806_ruleMicrosoft Defender AV spyware definition age must not exceed 7 days.
☐SV-213453r1192807_ruleMicrosoft Defender AV virus definition age must not exceed 7 days.
☐SV-213454r961161_ruleMicrosoft Defender AV must be configured to check for definition updates daily.
☐SV-213455r961086_ruleMicrosoft Defender AV must be configured for automatic remediation action to be taken for threat alert level Severe.
☐SV-213456r961092_ruleMicrosoft Defender AV must be configured to block executable content from email client and webmail.
☐SV-213457r961092_ruleMicrosoft Defender AV must be configured block Office applications from creating child processes.
☐SV-213458r961092_ruleMicrosoft Defender AV must be configured block Office applications from creating executable content.
☐SV-213459r961092_ruleMicrosoft Defender AV must be configured to block Office applications from injecting into other processes.
☐SV-213460r961092_ruleMicrosoft Defender AV must be configured to impede JavaScript and VBScript to launch executables.
☐SV-213461r961092_ruleMicrosoft Defender AV must be configured to block execution of potentially obfuscated scripts.
☐SV-213462r961092_ruleMicrosoft Defender AV must be configured to block Win32 imports from macro code in Office.
☐SV-213463r961092_ruleMicrosoft Defender AV must be configured to prevent user and apps from accessing dangerous websites.
☐SV-213464r961086_ruleMicrosoft Defender AV must be configured for automatic remediation action to be taken for threat alert level High.
☐SV-213465r961086_ruleMicrosoft Defender AV must be configured for automatic remediation action to be taken for threat alert level Medium.
☐SV-213466r961086_ruleMicrosoft Defender AV must be configured for automatic remediation action to be taken for threat alert level Low.
☐SV-278647r1192808_ruleMicrosoft Defender AV must block Adobe Reader from creating child processes.
☐SV-278648r1192809_ruleMicrosoft Defender AV must block credential stealing from the Windows local security authority subsystem.
☐SV-278649r1192810_ruleMicrosoft Defender AV must block untrusted and unsigned processes that run from USB.
☐SV-278650r1192811_ruleMicrosoft Defender AV must use advanced protection against ransomware.
☐SV-278651r1192812_ruleMicrosoft Defender AV must audit process creations originating from PSExec and WMI commands.
☐SV-278652r1192813_ruleMicrosoft Defender AV must audit persistence through WMI event subscription.
☐SV-278653r1192814_ruleMicrosoft Defender AV must audit executable files from running unless they meet a prevalence, age, or trusted list criterion.
☐SV-278654r1192815_ruleMicrosoft Defender AV must block Office communication application from creating child processes.
☐SV-278655r1192816_ruleMicrosoft Defender AV must block abuse of exploited vulnerable signed drivers.
☐SV-278656r1192817_ruleMicrosoft Defender AV must configure local administrator merge behavior for lists.
☐SV-278658r1207388_ruleMicrosoft Defender AV must control whether exclusions are visible to Local Admins.
☐SV-278659r1192819_ruleMicrosoft Defender AV must randomize scheduled task times.
☐SV-278660r1192820_ruleMicrosoft Defender AV must hide the Family options area.
☐SV-278661r1192821_ruleMicrosoft Defender AV must enable the file hash computation feature.
☐SV-278662r1192822_ruleMicrosoft Defender AV must enable extended cloud check.
☐SV-278668r1192823_ruleMicrosoft Defender AV must enable script scanning.
☐SV-278669r1192824_ruleMicrosoft Defender AV must enable real-time protection and Security Intelligence Updates during OOBE.
☐SV-278672r1192825_ruleMicrosoft Defender AV must enable network protection to be configured into block or audit mode on Windows Server.
☐SV-278674r1192826_ruleMicrosoft Defender AV must enable EDR in block mode.
☐SV-278675r1192827_ruleMicrosoft Defender AV must report Dynamic Signature dropped events.
☐SV-278676r1192828_ruleMicrosoft Defender AV must scan excluded files and directories during quick scans.
☐SV-278677r1192829_ruleMicrosoft Defender AV must convert warn verdict to block.
☐SV-278678r1192830_ruleMicrosoft Defender AV must enable asynchronous inspection.
☐SV-278679r1192831_ruleMicrosoft Defender AV must scan packed executables.
☐SV-278680r1192832_ruleMicrosoft Defender AV must enable heuristics.
☐SV-278863r1192833_ruleMicrosoft Defender AV must set cloud protection level to High.