# Windows Defender AV settings status
Get-MpPreference

# Enable real-time monitoring
Set-MpPreference -DisableRealtimeMonitoring 0

# Enable cloud-deliveredprotection
Set-MpPreference -MAPSReporting Advanced

# Enable sample submission
Set-MpPreference -SubmitSamplesConsent Always

# Enable checking signatures before scanning
Set-MpPreference -CheckForSignaturesBeforeRunningScan 1

# Enable behavior monitoring
Set-MpPreference -DisableBehaviorMonitoring 0

# Enable IOAV protection -  scans all downloaded files and attachments
Set-MpPreference -DisableIOAVProtection 0

# Enable script scanning
Set-MpPreference -DisableScriptScanning 0

# Enable removable drive scanning
Set-MpPreference -DisableRemovableDriveScanning 0

# Enable Block at first sight
Set-MpPreference -DisableBlockAtFirstSeen 0

# Enable potentially unwanted apps
Set-MpPreference -PUAProtection Enabled

# Schedule signature updates every 8 hours
Set-MpPreference -SignatureUpdateInterval 8

# Enable archive scanning
Set-MpPreference -DisableArchiveScanning 0

# Enable email scanning
Set-MpPreference -DisableEmailScanning 0

# Set cloud block level to 'High'
Set-MpPreference -CloudBlockLevel High

# Set cloud block timeout to 1 minute
Set-MpPreference -CloudExtendedTimeout 50

# Updating Windows Defender Exploit Guard settings
# Enabling Controlled Folder Access and setting to block mode
Set-MpPreference -EnableControlledFolderAccess Enabled 

# Enabling Network Protection and setting to block mode
Set-MpPreference -EnableNetworkProtection Enabled

# Enabling Exploit Guard ASR rules and setting to block mode. Some of these may block behavior that is acceptable in your organization, in this case please disable those specific rules. Learn more: https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-exploit-guard/attack-surface-reduction-exploit-guard"
# Block Office applications from injecting code into other processes
Add-MpPreference -AttackSurfaceReductionRules_Ids 75668C1F-73B5-4CF0-BB93-3ECF5CB7CC84 -AttackSurfaceReductionRules_Actions Enabled
# Block Office applications from creating executable content
Add-MpPreference -AttackSurfaceReductionRules_Ids 3B576869-A4EC-4529-8536-B80A7769E899 -AttackSurfaceReductionRules_Actions Enabled
# Block all Office applications from creating child processes
Add-MpPreference -AttackSurfaceReductionRules_Ids D4F940AB-401B-4EfC-AADC-AD5F3C50688A -AttackSurfaceReductionRules_Actions Enabled
# Block JavaScript or VBScript from launching downloaded executable content
Add-MpPreference -AttackSurfaceReductionRules_Ids D3E037E1-3EB8-44C8-A917-57927947596D -AttackSurfaceReductionRules_Actions Enabled
# Block execution of potentially obfuscated scripts
Add-MpPreference -AttackSurfaceReductionRules_Ids 5BEB7EFE-FD9A-4556-801D-275E5FFC04CC -AttackSurfaceReductionRules_Actions Enabled
# Block executable content from email client and webmail
Add-MpPreference -AttackSurfaceReductionRules_Ids BE9BA2D9-53EA-4CDC-84E5-9B1EEEE46550 -AttackSurfaceReductionRules_Actions Enabled
# Block Win32 API calls from Office macro
Add-MpPreference -AttackSurfaceReductionRules_Ids 92E97FA1-2EDF-4476-BDD6-9DD0B4DDDC7B -AttackSurfaceReductionRules_Actions Enabled
# Block process creations originating from PSExec and WMI commands
Add-MpPreference -AttackSurfaceReductionRules_Ids D1E49AAC-8F56-4280-B9BA-993A6D77406C -AttackSurfaceReductionRules_Actions Enabled
# Block untrusted and unsigned processes that run from USB
Add-MpPreference -AttackSurfaceReductionRules_Ids B2B3F03D-6A65-4F7B-A9C7-1C7EF74A9BA4 -AttackSurfaceReductionRules_Actions Enabled
# Use advanced protection against ransomware
Add-MpPreference -AttackSurfaceReductionRules_Ids C1DB55AB-C21A-4637-BB3F-A12568109D35 -AttackSurfaceReductionRules_Actions Enabled
# Block executable files from running unless they meet a prevalence, age, or trusted list criteria
Add-MpPreference -AttackSurfaceReductionRules_Ids 01443614-CD74-433A-B99E-2ECDC07BFC25 -AttackSurfaceReductionRules_Actions Enabled
# New in 1809
# Block credential stealing from the Windows local security authority subsystem (lsass.exe)
Add-MpPreference -AttackSurfaceReductionRules_Ids 9e6c4e1f-7d60-472f-ba1a-a39ef669e4b2 -AttackSurfaceReductionRules_Actions Enabled
# Block Office communication applications from creating child processes
Add-MpPreference -AttackSurfaceReductionRules_Ids 26190899-1602-49e8-8b27-eb1d0a1ce869 -AttackSurfaceReductionRules_Actions Enabled
# Block Adobe Reader from creating child processes
Add-MpPreference -AttackSurfaceReductionRules_Ids 7674ba52-37eb-4a4f-a9a1-f0f9a1619a2c -AttackSurfaceReductionRules_Actions Enabled
# New in 1903
# Block persistence through WMI event subscription
Add-MpPreference -AttackSurfaceReductionRules_Ids e6db77e5-3df2-4cf1-b95a-636979351e5b -AttackSurfaceReductionRules_Actions Enabled

# Check standard set of mitigations for Exploit protection
Start-Process "https://demo.wd.microsoft.com/Content/ProcessMitigation.xml"

# Enabling Exploit Protection"
Set-ProcessMitigation -PolicyFilePath "C:\NTK\WD\ProcessMitigation.xml"

# Enable Windows Defender Offline
Set-MpPreference -UILockdown 0

# Windows Defender AV settings status
Get-MpPreference

# Restart Computer
Restart-Computer