Suspicious Execution of Windows Defender Critical Binaries

Rule Info

Name
Suspicious Execution of Windows Defender Critical Binaries
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects suspicious execution of Windows Defender Binaries either executed from an unusual location or binary trying to masquerade as a legitimate Windows Defender binary. This behavior can be indicative of an attacker trying to hide their malicious binary by masquerading as a legitimate Windows Defender binary or some exploit trying to bypass Windows Defender.
Date
2026-07-15 00:00:00
Modified
None
Id
61ecba13-053a-4bd0-8436-c58d7f7dc174
Tags
attack.stealth attack.t1036.005 attack.t1036
Type
Nextron Sigma feed only (private)

Rule History