Windows Defender Reconnaissance - PowerShell

Rule Info

Name
Windows Defender Reconnaissance - PowerShell
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects attempts to gather detailed information about Windows Defender settings and status using Defender related commands. This behavior may indicate that an attacker is trying to assess the system's security configuration to identify potential weaknesses. Adversaries often perform reconnaissance to enumerate the system's security policies, configurations, and defenses. By understanding the current security posture, attackers can tailor their exploitation strategies to bypass defenses and achieve their objectives.
Date
2025-02-13 00:00:00
Modified
None
Id
69e977b0-3480-4ce2-afca-2c9dea270a84
Tags
attack.defense-evasion attack.t1562 attack.execution attack.t1059
Type
Nextron Sigma feed only (private)

Rule History