Registry Set for WinDefend Deletion

Rule Info

Name
Registry Set for WinDefend Deletion
Author
MalGamy
Description
Detects the deletion of the WinDefend registry key in attempt to disable Windows Defender.
Date
2024-10-23 00:00:00
Modified
None
Id
d65668c8-772a-4cc9-8c5e-b6cccf7d3f49
Tags
attack.persistence attack.t1112
Type
Nextron Sigma feed only (private)

Rule History