
Rule Info
Name
Windows Defender Deletion Attempt
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects attempts to delete Windows Defender related files and folders.
Adversaries may attempt to disable Windows Defender by deleting its files and folders to carry out their further malicious activities without getting caught
Date
2025-03-11 00:00:00
Modified
None
Id
4f4efbd4-6b3e-461e-b852-2ff4e974a9ce
Tags
attack.defense-evasion attack.t1562.001
Type
Nextron Sigma feed only (private)