M1049Antivirus / Antimalware
Signature + heuristic + cloud-based malware detection; a foundational protection layer used alongside modern NGAV/EDR.
Loading…
Executing malicious code
Techniques in this tactic (1)
Signature + heuristic + cloud-based malware detection; a foundational protection layer used alongside modern NGAV/EDR.
Advanced audit policy + command-line auditing + Sysmon + directory access auditing: the telemetry that detection requires.
Block common attack behaviors using Defender ASR rules and Office macro restrictions.
Allowlisting that permits only approved applications/scripts to run; blocks unknown code execution by default.
Platform protections (DEP, ASLR, CFG, CET) that block memory corruption and exploitation techniques.
Keep the number and use of privileged accounts to a minimum: Domain Admins hygiene, LAPS, JIT/PIM.
Narrows egress channels with DNS hardening (protective DNS/RPZ + sinkhole) and web proxy/filtering.
Blocking LOLBin/malware attacks by allowing only approved code, libraries, and scripts to execute.