Check: WNDF-AV-000075
Microsoft Defender Antivirus STIG:
WNDF-AV-000075
(in versions v2 r7 through v2 r6)
Title
Microsoft Defender AV must enable asynchronous inspection. (Cat II impact)
Discussion
Network protection includes performance optimization that allows block mode to asynchronously inspect long-lived connections, which might provide a performance improvement. This optimization can also help with app compatibility problems.
Check Content
Verify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Network Inspection System >> Turn on asynchronous inspection is set to "Enabled"; otherwise, this is a finding. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows Defender\NIS Criteria: If the value "AllowSwitchToAsyncInspection" is REG_DWORD = 1, this is not a finding. If the value is 0, this is a finding.
Fix Text
Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> MpEngine >> Turn on asynchronous inspection to "Enabled". Click "OK". Click "Apply".
Additional Identifiers
Rule ID: SV-278678r1144079_rule
Vulnerability ID: V-278678
Group Title: SRG-APP-000210
Expert Comments
CCIs
| Number | Definition |
|---|---|
| CCI-001170 |
Prevents the automatic execution of mobile code in organization-defined software applications. |
Controls
| Number | Title |
|---|---|
| SC-18(4) |
Prevent Automatic Execution |