Rule Info
Name
Suspicious Execution of Windows Defender Critical Binaries
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects suspicious execution of Windows Defender Binaries either executed from an unusual location
or binary trying to masquerade as a legitimate Windows Defender binary.
This behavior can be indicative of an attacker trying to hide their malicious binary by masquerading
as a legitimate Windows Defender binary or some exploit trying to bypass Windows Defender.
Reference
Date
2026-07-15 00:00:00
Modified
None
Id
61ecba13-053a-4bd0-8436-c58d7f7dc174
Tags
attack.stealth attack.t1036.005 attack.t1036
Type
Nextron Sigma feed only (private)
