Windows defense mechanisms

Windows defense mechanisms

Defense Mechanism Description
Microsoft Defender Antivirus Provides real-time antimalware protection using signatures, cloud protection, behavior monitoring, and other signals.
Windows Defender Firewall Enforces configured inbound and outbound network policies.
Microsoft Defender SmartScreen Evaluates sites, downloads, and application reputation and warns or blocks according to policy.
Exploit protection and ASR rules Separate controls for process exploit mitigations and behaviors commonly abused by malware. Older policy paths may use the “Exploit Guard” umbrella name.
Windows Defender Application Guard Isolates untrusted websites and applications using containerization, helping protect the system from browser-based threats.
Windows Sandbox Provides a temporary, isolated environment where untrusted applications can run without affecting the host system, ensuring safe testing.
BitLocker Offers full-disk encryption to safeguard data on a device, making it inaccessible if the hardware is lost or stolen.
Credential Guard Uses virtualization-based security (VBS) to isolate and secure user credentials and other sensitive information from compromise.
App Control for Business Application-control policies for trusted drivers, executables, scripts, and installers. “Device Guard” is retained mainly in older policy and registry names.
Attack Surface Reduction (ASR) Rules Enforce policies that restrict behaviors commonly exploited by malware, reducing potential entry points for attacks.
Windows Hello Provides biometric and PIN-based authentication methods that enhance user login security, reducing reliance on passwords.