Detection rules › By eventMicrosoft-Windows-Windows-Defender event 50077 detection rules reference this event. View event page.Sigma (4)Windows Defender Configuration Changes severity high T1562.001 Windows Defender Exclusions Added severity medium T1562.001 Windows Defender Exploit Guard Tamper severity high T1562.001 Windows Defender Submit Sample Feature Disabled severity low T1562.001 Splunk (3)Windows Defender ASR Registry Modification T1112 Windows Defender ASR Rule Disabled T1112 Windows Defender ASR Rules Stacking T1059, T1566.001, T1566.002