How to Detect Windows Attacks with Microsoft Defender ASR and Wazuh

· Original article ↗

Summary

A step-by-step guide to enabling Microsoft Defender ASR rules on Windows, forwarding Defender events to Wazuh, and creating alerts for blocked attack techniques and ASR configuration changes.

Key points

  • The guide configures five Microsoft Defender ASR rules in Block mode to restrict behaviors involving PSExec/WMI, WMI persistence, copied system tools, and Office applications.
  • Wazuh agents collect Defender Operational events 1121 for blocked activity and 5007 for configuration changes.
  • Custom Wazuh rules identify ASR events by rule GUID and generate alerts for the specific blocked behaviors.
  • Demonstrations show alerts for WMI process creation and persistence, copied system tools, Office-spawned processes, and Office-created executable files.
  • A separate rule detects changes to ASR rule configuration, helping surface potential tampering.
  • The setup uses a Wazuh 4.14.7 server and agent with a Windows 11 endpoint.

Article Details

Defense Focus
Detect and investigate blocked Microsoft Defender ASR activity and ASR configuration changes on Windows endpoints using Wazuh.
Detection Methods
  • Collect ASR events with IDs 1121 and 5007 from the Microsoft-Windows-Windows Defender/Operational event channel.
  • Match event 1121 to the ASR rule GUID in win.eventdata.iD and include the affected process path from win.eventdata.path in alerts.
  • Detect ASR rule-mode changes in event 5007 by matching win.system.message to ASR\Rules.
  • Use Wazuh Threat Hunting event filters for rule IDs 100701–100706 to review the corresponding alerts.
Data Sources
  • Microsoft-Windows-Windows Defender/Operational event channel
  • Windows event IDs 1121 (ASR block) and 5007 (configuration change)
  • Wazuh-decoded fields win.system.eventID, win.eventdata.iD, win.eventdata.path, win.system.message, and win.eventdata.new Value
Rule Types
  • Custom Wazuh XML rules: a base classifier for event ID 1121 and GUID-specific rules for ASR blocks
  • Custom Wazuh XML rule for ASR configuration changes, narrowed to ASR\Rules messages
Platforms
  • Windows endpoints
  • Wazuh server and dashboard
Defensive Actions
  • Enable the relevant Microsoft Defender ASR rules in Block mode on monitored Windows endpoints.
  • Configure the Wazuh agent to forward event IDs 1121 and 5007 from the Defender Operational event channel, then restart the agent.
  • Deploy and reload the custom Wazuh rules to alert on blocked activities and ASR rule-mode changes.
  • Investigate alerts using the reported ASR rule GUID and process path, and verify that configuration changes are authorized.
  • If Tamper Protection prevents an intended ASR configuration change, follow the article's procedure and re-enable Tamper Protection after configuration.

MITRE ATT&CK

Vendors

Products

Related Articles