Detection rules › Sigma

Windows Defender Real-time Protection Disabled

Severity
high
Author
Ján Trenčanský, frack113
Source
upstream

Detects disabling of Windows Defender Real-time Protection. As this event doesn't contain a lot of information on who initiated this action you might want to reduce it to a "medium" level if this occurs too many times in your environment

MITRE ATT&CK coverage

TacticTechniques
Defense EvasionT1562.001 Impair Defenses: Disable or Modify Tools

Event coverage

ProviderEvent IDTitle
Windows-Defender5001

Stages and Predicates

Stage 1: selection