Detection rules › Sigma

Windows Defender Virus Scanning Feature Disabled

Severity
high
Author
Ján Trenčanský, frack113
Source
upstream

Detects disabling of the Windows Defender virus scanning feature

MITRE ATT&CK coverage

TacticTechniques
Defense EvasionT1562.001 Impair Defenses: Disable or Modify Tools

Event coverage

ProviderEvent IDTitle
Windows-Defender5012

Stages and Predicates

Stage 1: selection