Detection rules › Sigma

Windows Defender Grace Period Expired

Severity
high
Author
Ján Trenčanský, frack113
Source
upstream

Detects the expiration of the grace period of Windows Defender. This means protection against viruses, spyware, and other potentially unwanted software is disabled.

MITRE ATT&CK coverage

TacticTechniques
Defense EvasionT1562.001 Impair Defenses: Disable or Modify Tools

Event coverage

ProviderEvent IDTitle
Windows-Defender5101

Stages and Predicates

Stage 1: selection