Rule Info
Name
Windows Defender Folder Invocation Through Short Name
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects suspicious command line patterns where a process is invoking a path within the Windows Defender folder using its short name (8.3 notation).
This technique may be used to execute or manipulate Windows Defender binaries while evading detection mechanisms that do not account for short path names.
Date
2026-01-29 00:00:00
Modified
None
Id
9f8e45b6-e3d7-42ca-9c69-89e03d14ea6d
Tags
attack.defense-evasion attack.t1027.010
Type
Nextron Sigma feed only (private)
