Defender Attack Surface Reduction Rules GUID Table
Pulled from Microsoft Learn on 1/2/25: https://learn.microsoft.com/en-us/defender-endpoint/attack-surface-reduction-rules-reference
| Rule | GUID |
|---|---|
| Block abuse of exploited vulnerable signed drivers | 56a863a9-875e-4185-98a7-b882c64b5ce5 |
| Process creation from Adobe Reader (beta) | 7674ba52-37eb-4a4f-a9a1-f0f9a1619a2c |
| Block Office application from creating child processes | d4f940ab-401b-4efc-aadc-ad5f3c50688a |
| Block credential stealing from the Windows local security authority subsystem | 9e6c4e1f-7d60-472f-ba1a-a39ef669e4b2 |