Detection rules › Sigma

Windows Defender Threat Detected

Severity
high
Author
Ján Trenčanský
Source
upstream

Detects actions taken by Windows Defender malware detection engines

MITRE ATT&CK coverage

TacticTechniques
ExecutionT1059 Command and Scripting Interpreter

Event coverage

ProviderEvent IDTitle
Windows-Defender1006
Windows-Defender1015
Windows-Defender1116
Windows-Defender1117

Stages and Predicates

Stage 1: selection