Elastic Defend high stable eql

Windows Defender Exclusions by Extension

Identifies modifications to the Windows Defender configuration settings to exclude specific executable file types by extension.

View Source

Detection Logic

registry where
 registry.value : ("exe", "pif", "scr", "js", "vbs", "wsh", "hta", "cpl", "jse", "vbe", "bat", "cmd", "dll", "ps?") and
 registry.data.strings : "0" and
 registry.path :
         ("HKLM\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Exclusions\\Extensions\\*",
          "HKEY_USERS\\S-1-5-21-*\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Exclusions\\Extensions\\*") and
 not (process.code_signature.status : ("trusted", "errorExpired", "errorCode_endpoint*") and
      not process.name : ("reg.exe", "powershell.exe", "rundll32.exe", "regsvr32.exe") and
      not process.executable : "?:\\Windows\\Microsoft.NET\\*")

Field Validations

Loading…

Comments (0)

Loading comments...