Skip to content
Microsoft Defender

Defender Event ID 1121: ASR rule blocked an operation

An attack surface reduction rule blocked an operationDefender event 1121 is logged when an attack surface reduction (ASR) rule in block mode stops an operation, such as LSASS access or Office child processes.
1121
Event ID
1121
Channel
Microsoft-Windows-Windows Defender/Operational
Provider
Microsoft-Windows-Windows Defender
Log file
Microsoft-Windows-Windows Defender%4Operational.evtx
Category
Antimalware
Default logging
Needs configuration

What event 1121 means

Event 1121 records a block by an attack surface reduction rule: Office spawning child processes, credential theft from LSASS, process creation from PsExec and WMI, obfuscated scripts and similar behaviors that ASR rules target. The event names the rule by GUID, the process that was blocked and the target.

ASR audit mode logs the same situations as event 1122 without blocking, which is how rules are usually tested before enforcement.

When it is logged

Audit policy / configuration

At least one attack surface reduction rule configured in block mode (Group Policy, Intune, or Set-MpPreference -AttackSurfaceReductionRules_Actions).

Key fields

FieldWhat it tells you
IDGUID of the ASR rule that fired.
PathTarget of the blocked operation (for example the process or file being accessed).
Process NameProcess whose operation was blocked.
Detection TimeWhen the block happened.

Common benign sources

  • Line-of-business apps and admin tools doing things ASR rules consider risky (Office add-ins, management agents creating processes via WMI).

What attackers do that produces it

  • LSASS access attempts blocked by the credential-stealing rule.
  • Macro documents spawning scripts or executables, blocked by the Office rules.
  • Lateral movement through PsExec or WMI process creation, blocked by the corresponding rule.

Investigation tips

  • Map the rule GUID to its name in Microsoft's ASR rules reference.
  • Investigate the blocked process chain with 4688 / Sysmon 1; a block means the attempt happened.

MITRE ATT&CK techniques

TechniqueTactics
T1003.001 OS Credential Dumping: LSASS MemoryCredential Access

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

2 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 2

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading