Microsoft enables Microsoft Defender 's " Attack Surface Reduction " feature by default to prevent hackers from attempting to steal Windows credentials from the LSASS process.

See also: Microsoft: Support for Windows 10 20H2 ends in May
When malicious users compromise a network, they try to spread laterally to other devices, stealing credentials or using exploits.
One of the most common methods for stealing credentials in Windows is to gain administrator privileges on a compromised device and then perform a memory dump on the Local Security Authority Server Service (LSASS) running in Windows.
This memory dump contains NTLM hashes of the Windows credentials of users who were logged on to the computer, which can be used for clear-text passwords or Pass-the-Hash to log on to other devices.
While Microsoft Defender blocks malware, an LSASS memory dump can be transferred to a remote computer to dump credentials without fear of being blocked.
See also: Microsoft: Fixes a bug in Defender that allows malware scans to be bypassed
To prevent malicious users from abusing LSASS memory, Microsoft has introduced security features that block access to the LSASS process.

One of these security features is Credential Guard, which isolates the LSASS process in a virtual container that prevents access by other processes.
However, this feature may lead to conflicts with drive programs or applications, resulting in some organizations not enabling it.
As a way to mitigate Windows credential theft without causing the conflicts introduced by Credential Guard, Microsoft will soon enable a Microsoft Defender Attack Surface Reduction (ASR) feature by default.
This feature prevents processes from opening the LSASS process and dumping its memory, even if they have administrator privileges.
This new change was discovered this week by security researcher Kostas, who spotted an update in Microsoft's ASR rules documentation.
See also: Microsoft Defender Preview is available for Windows and Android
Because attack surface reduction rules tend to introduce false positives and a lot of noise into event logs, Microsoft has previously not enabled the security feature by default.
However, the company has recently begun to choose security over convenience, removing common features used by Windows administrators and users that increase attack surfaces.
