Recovering from Attack Surface Reduction rule shortcut deletions

Guidance on how to recover from short-cut deletions including PowerShell script.

TECHCOMMUNITY.MICROSOFT.COM
MDE-PowerBI-Templates/AddShortcuts.ps1 at master · microsoft/MDE-PowerBI-Templates

A respository for MDATP PowerBI Templates. Contribute to microsoft/MDE-PowerBI-Templates development by creating an account on GitHub.

GitHub

Follow-up to #ASRmageddon (deleted shortcuts in #Windows due to an ASR rule and triggered by a broken Defender update). Why home users with #DefenderUI were affected and how to get the .lnk files back.

https://borncity.com/win/2023/01/16/asrmageddon-warum-privatnutzer-betroffen-waren-wie-man-shortcuts-restauriert/

ASRmageddon: Why private users were affected, how to restore shortcuts

[German]Friday January 13, 2023 Windows users worldwide were affected by a buggy Defender signature update that deleted desktop shortcuts and more via an ASR rule. In a follow-up, I shed some light on why even home Windows 10/11 users could have been affected. And there's still an approach to restor

Born's Tech and Windows World

Nachlese zu #ASRmageddon (gelöschte Verknüpfungen in #Windows auf Grund einer ASR-Regel und getriggert durch ein kaputtes Defender Update). Warum Privatanwender mit #DefenderUI betroffen waren und wie man die .lnk-Dateien zurück bekommt.

https://www.borncity.com/blog/2023/01/16/asrmageddon-warum-privatnutzer-betroffen-waren-wie-man-shortcuts-restauriert/

ASRmageddon: Warum Privatnutzer betroffen waren, wie man Shortcuts restauriert

[English]Freitag den 13. Januar 2023 waren weltweit Windows-Nutzer von einem fehlerhaften Defender Signatur-Update betroffen, welches über eine ASR-Regel Desktop-Verknüpfungen und mehr löschte. In einer Nachbereitung werfe ich ein Licht darauf, warum auch private Windows 10/11-Nutzer betroffen sein

Borns IT- und Windows-Blog
What if all of this was a ploy to get people to use advanced hunting / E5 #asr #asrrules #defender #signature #ASRmagedon #ASRmageddon

Microsoft does a lot of good security work these days, but this time I guess you could say they…
( •_•)>⌐□-□
took shortcuts

#ASRmageddon

https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/recovering-from-attack-surface-reduction-rule-shortcut-deletions/ba-p/3716011

Recovering from Attack Surface Reduction rule shortcut deletions

Guidance on how to recover from short-cut deletions including PowerShell script.

TECHCOMMUNITY.MICROSOFT.COM

Giving Mastodon a go, finally had my resolve broken with the 3rd party client issues.

Absolutely no idea how to use Mastodon. #introductions

The first post on my home... #ASRMageddon . Yep - this place is for me

Microsoft in talks to invest $10 bln in ChatGPT-owner OpenAI, Semafor reports

Microsoft Corp <a href="https://www.reuters.com/companies/MSFT.O/"target="_blank">(MSFT.O)</a> is in talks to invest $10 billion in <a href="https://www.reuters.com/technology/chatgpt-what-is-openais-chatbot-what-is-it-used-2022-12-05/" target="_blank">ChatGPT-owner OpenAI</a> as part of funding that will value the firm at $29 billion, Semafor reported on Monday, citing people familiar with the matter.

Reuters
Recovering from Attack Surface Reduction rule shortcut deletions

Guidance on how to recover from short-cut deletions including PowerShell script.

TECHCOMMUNITY.MICROSOFT.COM
This kind of thing massively sets back security improvement programs, so relieved I'm not trying to recover from this after having persuaded people to deploy it... https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-22h2#2998msgdesc #asrmageddon
Windows 11, version 22H2 known issues and notifications

View announcements and review known issues and fixes for Windows 11, version 22H2