Skip to content

[Feature] - ASR Rule Redundancy #178

@PatrickQuinane

Description

@PatrickQuinane

Is your feature request related to a problem? Please describe.
We currently use ASR Rule "Block credential stealing from the Windows local security authority subsystem". We have been having a number of detections against this rule on svchost.exe, which we don't want to create an exclusion for, as this is dangerous, but we also believe it could be causing performance issues on the device.

Describe the solution you'd like
Microsoft states on [their documentation for this rule](Block credential stealing from the Windows local security authority subsystem) that if you have LSA Protection enabled, this ASR rule is not required. LSA Protection is enabled by default on all Windows 11 22H2 devices anyways. I believe the corresponding Intune policy is RunAsPPL.

Please let me know if you would like any further information/documentation.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions