ConfigureDefender utility for Windows 10/11

Hard_Configurator Tools
1,904 Replies 563,784 Views
Is not these two are the required for BAFS?
They are enabled by default!

View attachment 295800

BAFS is triggered after file download via Edge/Chrome browsers. It does not work on Malware tests when files are executed from flash drives or from network shares.
 
The prevalence/age criteria ASR rule works for DLLs when they are executed via such LOLBins as:
Netsh, Odbcconf, OfflineScannerShell, Pcalua (DLL --> CPL), RunDLL32, Register-CimProvider, RegSvr32, Control (DLL --> CPL), etc.
 
Last edited:
It is not related in any way. So yes, keep it on High. (y)
side note @Kongo & @Andy Ful I ran ConfigureDefender 4100 on win10 and it was blocked: DeepInstinct (secondary av)
threat prevented powershell ...s Defender; was identified as a trojan and is now blocked...
... DI Behavioral Analysis / malicious powershell command execution

so I went into the console and disabled DeepInstinct and re-enabled after the required reboot.
Just something to know...
 
side note @Kongo & @Andy Ful I ran ConfigureDefender 4100 on win10 and it was blocked: DeepInstinct (secondary av)
threat prevented powershell ...s Defender; was identified as a trojan and is now blocked...
... DI Behavioral Analysis / malicious powershell command execution

so I went into the console and disabled DeepInstinct and re-enabled after the required reboot.
Just something to know...
Some security solutions are hypersensitive to running PS commands, regardless of the command nature.
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top