Detection rules › By eventMicrosoft-Windows-Windows-Defender event 11214 detection rules reference this event. View event page.Sigma (2)LSASS Access Detected via Attack Surface Reduction severity high T1003.001 PSExec and WMI Process Creations Block severity high T1047, T1569.002 Splunk (2)Windows Defender ASR Block Events T1059, T1566.001, T1566.002 Windows Defender ASR Rules Stacking T1059, T1566.001, T1566.002