
Rule Info
Name
Windows Defender Permission Modification Using Icacls
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects attempts to modify permissions on Windows Defender files using icacls command.
This technique is often used by Threat Actors or Malware Group to disable or bypass security features, allowing the malware to operate without interference from Windows Defender.
The command typically involves granting full control to the Everyone group on critical Windows Defender files, which can lead to potential system compromise.
Date
2025-04-04 00:00:00
Modified
None
Id
99334455-3344-4433-a123-b456c789d012
Tags
attack.defense-evasion attack.t1562.001
Type
Nextron Sigma feed only (private)