Check: WNDF-AV-000055
Microsoft Defender Antivirus STIG:
WNDF-AV-000055
(in version v2 r6)
Title
Microsoft Defender AV must randomize scheduled task times. (Cat II impact)
Discussion
In Microsoft Defender Antivirus, randomize the start time of the scan to any interval from 0 to 23 hours. By default, scheduled tasks begin at a random time within four hours of the time specified in Task Scheduler.
Check Content
Verify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Randomize scheduled task times is set to "Enabled"; otherwise, this is a finding. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows Defender Criteria: If the value "RandomizeScheduleTaskTimes" is REG_DWORD = 1, this is not a finding. If the value is 0, this is a finding.
Fix Text
Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Randomize scheduled task times to "Enabled". Click "OK". Click "Apply".
Additional Identifiers
Rule ID: SV-278659r1144055_rule
Vulnerability ID: V-278659
Group Title: SRG-APP-000278
Expert Comments
CCIs
| Number | Definition |
|---|---|
| CCI-001242 |
The organization configures malicious code protection mechanisms to perform real-time scans of files from external sources at endpoints as the files are downloaded, opened, or executed in accordance with organizational security policy. |
Controls
| Number | Title |
|---|---|
| No controls are assigned to this check |