Rule Info
Name
Windows Defender Critical Binary Deletion
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects the deletion of critical Windows Defender binaries which could indicate an attempt to disable or manipulate Windows Defender.
Date
2026-01-29 00:00:00
Modified
None
Id
f87c7653-c52d-4d20-954a-f09944e21b34
Tags
attack.defense-evasion attack.t1562.001
Type
Nextron Sigma feed only (private)
