Recon Windows Defender Settings via Registry

Rule Info

Name
Recon Windows Defender Settings via Registry
Author
Swachchhana Shrawan Poudel (Nextron Systems)
Description
Detects attempts to read Windows Defender settings directly via the registry. Such activity may indicate reconnaissance efforts by malware or attackers to understand and potentially disable security measures.
Date
2025-02-13 00:00:00
Modified
None
Id
a31af362-17a7-46b3-9316-248fbdbaf07a
Tags
attack.discovery attack.t1518.001
Type
Nextron Sigma feed only (private)

Rule History