How to Detect Windows Attacks with Microsoft Defender ASR and Wazuh

Summary
A step-by-step guide to enabling Microsoft Defender ASR rules on Windows, forwarding Defender events to Wazuh, and creating alerts for blocked attack techniques and ASR configuration changes.
Key points
- The guide configures five Microsoft Defender ASR rules in Block mode to restrict behaviors involving PSExec/WMI, WMI persistence, copied system tools, and Office applications.
- Wazuh agents collect Defender Operational events 1121 for blocked activity and 5007 for configuration changes.
- Custom Wazuh rules identify ASR events by rule GUID and generate alerts for the specific blocked behaviors.
- Demonstrations show alerts for WMI process creation and persistence, copied system tools, Office-spawned processes, and Office-created executable files.
- A separate rule detects changes to ASR rule configuration, helping surface potential tampering.
- The setup uses a Wazuh 4.14.7 server and agent with a Windows 11 endpoint.
Article Details
- Defense Focus
- Detect and investigate blocked Microsoft Defender ASR activity and ASR configuration changes on Windows endpoints using Wazuh.
- Detection Methods
- Collect ASR events with IDs 1121 and 5007 from the Microsoft-Windows-Windows Defender/Operational event channel.
- Match event 1121 to the ASR rule GUID in win.eventdata.iD and include the affected process path from win.eventdata.path in alerts.
- Detect ASR rule-mode changes in event 5007 by matching win.system.message to ASR\Rules.
- Use Wazuh Threat Hunting event filters for rule IDs 100701–100706 to review the corresponding alerts.
- Data Sources
- Microsoft-Windows-Windows Defender/Operational event channel
- Windows event IDs 1121 (ASR block) and 5007 (configuration change)
- Wazuh-decoded fields win.system.eventID, win.eventdata.iD, win.eventdata.path, win.system.message, and win.eventdata.new Value
- Rule Types
- Custom Wazuh XML rules: a base classifier for event ID 1121 and GUID-specific rules for ASR blocks
- Custom Wazuh XML rule for ASR configuration changes, narrowed to ASR\Rules messages
- Platforms
- Windows endpoints
- Wazuh server and dashboard
- Defensive Actions
- Enable the relevant Microsoft Defender ASR rules in Block mode on monitored Windows endpoints.
- Configure the Wazuh agent to forward event IDs 1121 and 5007 from the Defender Operational event channel, then restart the agent.
- Deploy and reload the custom Wazuh rules to alert on blocked activities and ASR rule-mode changes.
- Investigate alerts using the reported ASR rule GUID and process path, and verify that configuration changes are authorized.
- If Tamper Protection prevents an intended ASR configuration change, follow the article's procedure and re-enable Tamper Protection after configuration.
MITRE ATT&CK
T1021.002 · SMB/Windows Admin SharesThe article's Wazuh rule maps ASR-blocked process creation through PSExec or WMI to this technique.T1036.003 · Rename Legitimate UtilitiesThe article's Wazuh rule detects ASR-blocked execution of a copied or impersonated system tool.T1047 · Windows Management InstrumentationThe article's Wazuh rule maps an ASR block of process creation through WMI to this technique.T1059 · Command and Scripting InterpreterThe article's Wazuh rule maps ASR-blocked execution of a file created by an Office application to this technique.T1204.002 · Malicious FileThe article's Wazuh rule maps an ASR-blocked Office application child-process attempt, demonstrated with a macro, to this technique.T1546.003 · Windows Management Instrumentation Event SubscriptionThe article's Wazuh rule detects an ASR-blocked attempt to create a permanent WMI event subscription.T1562.001 · Disable or Modify ToolsThe article's Wazuh rule uses Defender event 5007 to detect ASR rule-mode configuration changes.T1569.002 · Service ExecutionThe article's Wazuh rule maps ASR-blocked process creation through PSExec or WMI to this technique.T1570 · Lateral Tool TransferThe article's Wazuh rule maps ASR-blocked process creation through PSExec or WMI to this technique.
Vendors
Products
Microsoft DefenderMicrosoft Defender Attack Surface Reduction (ASR) rules help protect Windows endpoints by restricting behaviors commonly abused by malware and threat actors.Microsoft Defender Attack Surface Reduction (ASR)Microsoft Defender Attack Surface Reduction (ASR) rules help protect Windows endpoints by restricting behaviors commonly abused by malware and threat actors.Microsoft OfficeMicrosoft Office installed.WazuhThe Wazuh unified XDR and SIEM platform provides centralized visibility into security events across monitored endpoints.Windows 11A Windows 11 endpoint with: