Windows Defender Service Disabled (Extended) - Registry

Rule Info

Name
Windows Defender Service Disabled (Extended) - Registry
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects registry modifications that attempt to disable Windows Defender service at startup or disable it completely. This could be indicative of an attacker trying to disable security features to evade detection.
Date
2025-05-16 00:00:00
Modified
None
Id
1f0ebca6-b9d1-4a37-a343-3d70b3e76456
Tags
attack.defense-evasion attack.t1562.001
Type
Nextron Sigma feed only (private)

Rule History