Jump to content

Recommended Posts

Posted

Yep,

If you done have FSRM installed on server in question run the script reboot then run again it will then created the file screen templates.

I already had FSRM on one server so just ran the script. It knew I had it installed but just created the screen templates

Posted

Yeh I've just implemented FSRM too. It's such a good bit of software and the guy who made the powershell scripts is a saint!! Literally one click and 5 mins per server and job done.

 

Now that I've got this software on im gonna start adding some more lists. No more .bat .lnk .exe etc etc for my users!!

Posted

As mentioned in another thread - Just check your FileScreens before you do this as you could end up losing existing ones - Part of the script deletes the File Screen and then re-creates a new one. If you have additional file screens on the default shares they will be lost. I've just remembered that I had an media file block on one of my shares and that's gone.

 

If you are using the original script from this thread then the one linked by @caffrey wont include the powershell command to automatically block mapped drives for that user. I've applied both at the minute but will be looking to combine them in the future.

Posted
or mp3's or swf or mpg or avis..... MWA HA HA H AH AHA... (we have a separate shared area for our multimedia students ;)
  • Thanks 1
  • 5 months later...
Posted (edited)

Click the link for more details.

 

Windows Defender Exploit Guard: Reduce the attack surface against next-generation malware

 

Windows Defender Exploit Guard is a new set of intrusion prevention capabilities that ships with the Windows 10 Fall Creators Update. The four components of Windows Defender Exploit Guard are designed to lock down the device against a wide variety of attack vectors and block behaviors commonly used in malware attacks, while enabling enterprises to balance their security risk and productivity requirements.

 

The four components of Windows Defender Exploit Guard are:

 

  • Attack Surface Reduction (ASR): A set of controls that enterprises can enable to prevent malware from getting on the machine by blocking Office-, script-, and email-based threats
  • Network protection: Protects the endpoint against web-based threats by blocking any outbound process on the device to untrusted hosts/IP through Windows Defender SmartScreen
  • Controlled folder access: Protects sensitive data from ransomware by blocking untrusted processes from accessing your protected folders
  • Exploit protection: A set of exploit mitigations (replacing EMET) that can be easily configured to protect your system and applications

Attack Surface Reduction (ASR): Intelligence to control the surface area of the device

Email and Office applications are generally thought of as keystones of enterprise productivity, yet they are the most common vector for attacks and can cause nightmares for security administrators. Both Office and email serve as simple and easy ways to distribute mechanism for bad actors to kick off malware and fileless attacks. Although Office macros and scripts have many productive use cases, malicious actors can use them to directly perform exploits that operate entirely in memory and are often undetectable by traditional AV techniques. All it takes is for a single user to enable macros on a legitimate-looking Office file, or to open an email attachment that executes a malicious PowerShell script, to compromise a machine.

 

Attack Surface Reduction provides enterprises with a set of built-in intelligence that can block the underlying behaviors used by these malicious documents to execute without hindering productive scenarios. By blocking malicious behaviors independent of what the threat or exploit is, ASR can protect enterprises from never before seen zero-day attacks like the recently discovered CVE-2017-8759, CVE-2017-11292, and CVE-2017-11826.

 

The different behaviors ASR provides coverage for in Fall Creators Updated are split among Office, scripts, and email.

 

For Office apps, ASR can:

 

  • Block Office apps from creating executable content
  • Block Office apps from launching child process
  • Block Office apps from injecting into process
  • Block Win32 imports from macro code in Office
  • Block obfuscated macro code

Although malicious Office macros are oftentimes responsible for utilizing techniques like injection and launching of executables, ASR can also protect end-users from emerging exploits like DDEDownloader, which has been recently gaining in popularity. This exploit uses the Dynamic Data Exchange (DDE) popup in Office Documents to run a PowerShell downloader; however, in doing so, it launches a child process that the corresponding child process rule blocks.

 

For script, ASR can:

 

  • Block malicious JavaScript, VBScript, and PowerShell codes that have been obfuscated
  • Block JavaScript and VBScript from executing payload downloaded from internet

To highlight the intelligence behind ASR, we can look at how it can address obfuscated code as an example; in this case, there is a machine learning model powering our obfuscation detection capabilities that gets retrained multiple times per week in our cloud protection service. The model is updated on client, where it interfaces with Antimalware Scan Interface (AMSI) to make a determination on whether or not a script has been obfuscated for malicious purposes. When a high-confidence match occurs, any attempt made to access the script is blocked.

 

For email, ASR can:

 

  • Block execution of executable content dropped from email (webmail/mail-client)

Enterprise administrators can set policies on their corporate email (e.g., Office 365) to limit the files that can be delivered to end user inboxes. However, they don’t have control over the files that are delivered via personal email on company devices. Given the increase in spear-phishing, employees' personal emails are also targeted and need to be protected. ASR enables enterprise administrators to apply file policies on personal email for both webmail & mail-clients on company devices.

 

For any line of business applications running within your enterprise, there is the capability to customize file and folder based exclusions if your applications include unusual behaviors that may be impacted by ASR detection.

 

ASR has a dependency on Windows Defender Antivirus being the primary AV on the device and its real-time protection feature must be enabled. The Windows 10 Security baseline recommends enabling most of the rules in Block Mode to protect your devices from these threat vectors.

Edited by Arthur
  • Thanks 4
Posted
Also if your looking for the GPO ASR its in Windows components > Windows Defender Anti-Virus > Exploit Guard and not Windows components > Exploit Guard which only has 1 policy.
  • 3 months later...
Posted
Hi Arthur. Where is the Block Flash activation in Office Documents policy within the ADMX templates. I can't seem to find it by manually searching or via a Google search. It'll just be me being thick though! :confused:
Posted
Where is the Block Flash activation in Office Documents policy within the ADMX templates.

Once you have copied SecGuide.admx and SecGuide.adml to your central PolicyDefinitions folder from the download link above (the .adml goes in the en-US subfolder btw) you will find the policy at:

 

Computer Configuration > Policies > Administrative Templates > MS Security Guide > [b]Block Flash activation in Office documents[/b]

  • Thanks 1
Posted
Will this prevent embedded clips such as from YouTube from working if you enable Block Flash activation in Office documents ?

 

I wouldn't have thought so as YouTube uses HTML5, not Flash.

Posted
Will this prevent embedded clips such as from YouTube from working if you enable Block Flash activation in Office documents ?

Not if you are using PowerPoint 2013 or 2016. @Bob_the_Goon is correct.

 

https://support.office.com/en-us/article/are-you-having-video-or-audio-playback-issues-e0a94444-8ea7-4a00-974b-6ad0d6edc4b1?NS=POWERPNT&Version=16&SysLcid=1033&UiLcid=1033&AppVer=ZPP160&HelpId=103448&ui=en-US&rs=en-US&ad=US

 

Google recently made a change where it has retired the Flash Player infrastructure that PowerPoint 2010 depends upon for playing YouTube videos.

 

PowerPoint 2013 and PowerPoint 2016 are based on the HTML5 video playback infrastructure (instead of Flash Player) and are thus unaffected for the most part.

 

We are aware of the issue in PowerPoint 2010 and are investigating what we can do, but practically speaking, the most effective method of resolving this issue quickly is moving to a newer version of Office (2013 or 2016). You can also use PowerPoint Online, which is free and can be used with a Microsoft account (Hotmail, outlook.com, live.com). PowerPoint Online allows for the insertion and playing of YouTube videos.

Posted
Imagine what will happen if the kids realise they can play games with just a pencil and paper, or even just in their own imagination, how will that be stopped?
Posted
Imagine what will happen if the kids realise they can play games with just a pencil and paper, or even just in their own imagination, how will that be stopped?

 

Teacher Intervention will stop it. Much easier to see people with a pencil each drawing lines on a page full of dots (that's what I can remember doing) and making squares than minimising an Excel spreadsheet.

 

I've implemented the GPO to prevent the Students playing Flash games in Excel so we'll see how long it lasts before they all find a workaround. Now just as long as we dont teach them to embed Flash in to a website using Serif WebPlus, oh hang on a minute!...

  • 2 weeks later...
Posted

Security baseline for Office 2016 and Office 365 ProPlus apps – FINAL

 

Download: Office-2016-baseline.zip

 

Microsoft is pleased to announce the final release of the recommended security configuration baseline settings for Microsoft Office Professional Plus 2016 and Office 365 ProPlus 2016 apps. There are no changes from the draft release we published a few weeks ago, other than minor corrections within the spreadsheet.
Posted
It's always a good idea to have multiple layers of security rather than relying on a single product (even more so with AV software which tends to be quite buggy). :)

 

...which tends to be a way to run code at SYSTEM level just be emailing it to someone

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...