Windows Defender Reconnaissance

Rule Info

Name
Windows Defender Reconnaissance
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects reconnaissance attempts to query Windows Defender settings and status using PowerShell commands. This can be indicative of reconnaissance activities performed by an attacker to understand the security posture of the system. Adversaries often perform reconnaissance to enumerate the system's security policies, configurations, and defenses. By understanding the current security posture, attackers can tailor their exploitation strategies to bypass defenses and achieve their objectives.
Date
2025-02-13 00:00:00
Modified
None
Id
3de64190-412d-4d5f-ab61-06924d4014df
Tags
attack.discovery attack.t1518.001
Type
Nextron Sigma feed only (private)

Rule History