Rule Info
Name
Registry Set for WinDefend Deletion
Author
MalGamy
Description
Detects the deletion of the WinDefend registry key in attempt to disable Windows Defender.
Date
2024-10-23 00:00:00
Modified
None
Id
d65668c8-772a-4cc9-8c5e-b6cccf7d3f49
Tags
attack.persistence attack.t1112
Type
Nextron Sigma feed only (private)