IronSights

Detection & response

Attack Surface ReductionASR

A set of Microsoft Defender for Endpoint rules that block common attack techniques — such as Office macro execution of child processes, credential dumping, and malicious script execution — at the endpoint level.

Also known asASRASR rulesattack surface reduction rules

In plain English

ASR rules are pre-built guardrails in Windows that stop common attack techniques before they can do damage. They include blocking Office applications from spawning executable processes (a key ransomware delivery vector), preventing credential dumping from memory, and stopping scripts from running from suspicious locations.

Keep learning

More terms in the IronSights Glossary.