Defender Event ID 1121: ASR rule blocked an operation
- Event ID
- 1121
- Channel
- Microsoft-Windows-Windows Defender/Operational
- Provider
- Microsoft-Windows-Windows Defender
- Log file
- Microsoft-Windows-Windows Defender%4Operational.evtx
- Category
- Antimalware
- Default logging
- Needs configuration
What event 1121 means
Event 1121 records a block by an attack surface reduction rule: Office spawning child processes, credential theft from LSASS, process creation from PsExec and WMI, obfuscated scripts and similar behaviors that ASR rules target. The event names the rule by GUID, the process that was blocked and the target.
ASR audit mode logs the same situations as event 1122 without blocking, which is how rules are usually tested before enforcement.
When it is logged
At least one attack surface reduction rule configured in block mode (Group Policy, Intune, or Set-MpPreference -AttackSurfaceReductionRules_Actions).
Key fields
| Field | What it tells you |
|---|---|
| ID | GUID of the ASR rule that fired. |
| Path | Target of the blocked operation (for example the process or file being accessed). |
| Process Name | Process whose operation was blocked. |
| Detection Time | When the block happened. |
Common benign sources
- Line-of-business apps and admin tools doing things ASR rules consider risky (Office add-ins, management agents creating processes via WMI).
What attackers do that produces it
- LSASS access attempts blocked by the credential-stealing rule.
- Macro documents spawning scripts or executables, blocked by the Office rules.
- Lateral movement through PsExec or WMI process creation, blocked by the corresponding rule.
Investigation tips
- Map the rule GUID to its name in Microsoft's ASR rules reference.
- Investigate the blocked process chain with 4688 / Sysmon 1; a block means the attempt happened.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1003.001 OS Credential Dumping: LSASS Memory | Credential Access |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
2 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 2
- HighLSASS Access Detected via Attack Surface ReductionRule by Markus Neis, SigmaHQ, DRL 1.1
- HighPSExec and WMI Process Creations BlockRule by Bhabesh Raj, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.