Another useful thread for defenders.  Powerful auditing/blocking;

There's some useful stuff in the comments too.  If you are using Windows Defender Application Control;

Microsoft recommended block rules (Windows 10) - Windows security
View a list of recommended block rules, based on knowledge shared between Microsoft and the wider security community.
Microsoft recommended driver block rules (Windows 10) - Windows security
View a list of recommended block rules to block vulnerable third-party drivers discovered by Microsoft and the security research community.