Link to this headingAntivirus
Link to this headingWindows Defender
Link to this headingMicrosoft Active Protection Service (MAPS)
Enable MAPS:
# Enable MAPS reporting (Advanced Membership)
# Automatic safe sample submission
# High blocking level
# Extended cloud timeout
Enable MAPS through Group Policy:
# Enable MAPS Advanced Membership
# Enable Block at First Sight
# Configure sample submission (1 = send safe samples)
# Set high cloud protection level
# Configure extended cloud check timeout (50 seconds)
Enable Ransomware Protections:
# Enable Controlled Folder Access (Ransomware Protection)
# Add protected folders (optional)
# Allow specific applications through Controlled Folder Access
Link to this headingConfiguration and Hardening
Set Update interval:
# Update signatures every hour
# Check for signatures before each scan
Block security tools:
# Enable PUA protection
Block Common Microsoft attack vectors:
# Enable Attack Surface Reduction rules
)) {
}
Additional resources:
- Comprehensive Windows Defender hardening guide - Detailed configuration and security recommendations
For more Windows security configurations, see [Windows hardening](/Blue Team/Windows/Windows Hardning).