Elastic Defend high stable eql
Windows Defender Exclusions by Extension
Identifies modifications to the Windows Defender configuration settings to exclude specific executable file types by extension.
Detection Logic
registry where
registry.value : ("exe", "pif", "scr", "js", "vbs", "wsh", "hta", "cpl", "jse", "vbe", "bat", "cmd", "dll", "ps?") and
registry.data.strings : "0" and
registry.path :
("HKLM\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Exclusions\\Extensions\\*",
"HKEY_USERS\\S-1-5-21-*\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Exclusions\\Extensions\\*") and
not (process.code_signature.status : ("trusted", "errorExpired", "errorCode_endpoint*") and
not process.name : ("reg.exe", "powershell.exe", "rundll32.exe", "regsvr32.exe") and
not process.executable : "?:\\Windows\\Microsoft.NET\\*") Field Validations
Loading…
Comments (0)
Loading comments...