Block at first sight
BAFS is one of the most visible ways cloud-delivered protection can be applied practically. Malicious executable files are a serious concern, and this includes non-portable ones such as Office macros. As of Windows 10 1803, an MDAV client with BAFS enabled will query the hash value of executables with mark of the web (MOTW) against the cloud protection service. If the file is new to the cloud telemetry dataset but may pose a risk, it is locked for up to 1 minute and a sample is uploaded (based on your tenant’s geography) for further analysis. If a verdict of malicious is returned before this timeout period, execution is blocked. Decisions are usually returned in milliseconds based on metadata, but the additional time allows for analysis at levels further along the processing chain.
What is MOTW?
Files downloaded from the internet (based on zones) are given a MOTW, contained in an NTFS stream, by Windows, if the downloading/extracting software supports...