I've followed KB93741 Knowledge Center - REGISTERED - Attack Surface Reduction content (mcafee.com)
and am testing it with an xlsm file to see if I can trigger the ASROFFMACRO rule.
So far I have been unable to get any detections, even though I have a file with macros in it.
I've followed all the instructions, cleared the cache and done a right-click scan on the file but it's not detecting it. Although the article does not mention it, I assume these expert rules can be applied via ePO, so attached is a screen shot of my settings, currently set to report only.
Has anyone else managed to get these ASR rules to work?