Attack Surface Reduction (ASR) provides proactive defense by identifying threats based on their content and activity patterns rather than just known signatures. You can enable managed ASR rules to detect ransomware behavior and bait file creation attempts during on-access scans without requiring complex expert rules.
Tip
For a complete list of Attack Surface Reduction (ASR) content that can be enabled using Expert Rules, see KB93741.
In ePO, select Menu → Policy → Policy Catalog.
Select Endpoint Security Threat Prevention, then select On-Access Scan.
Select Edit in My Default policy.
Locate the Ransomware Protections section, then select Add.
Select the following checkboxes to enable protections:
Detect unknown ransomware based on behaviour – Enables the rule to identify processes exhibiting ransomware-like activity.
Create ransomware bait files on file system – Creates ransomware bait file and enables the rule to block the creation of files commonly associated with ransomware attacks.
Select Save.