Sagan high stable other

[WINDOWS-POWERSHELL] Microsoft Defender Security Registry Access

[WINDOWS-POWERSHELL] Microsoft Defender Security Registry Access

View Source

Detection Logic

alert any $HOME_NET any -> $HOME_NET any (msg:"[WINDOWS-POWERSHELL] Microsoft Defender Security Registry Access"; program: *PowerShell*; json_map:"event_id",".EventID"; json_map:"message",".RenderedDescription"; event_id:400,800,4103,4104,800; meta_content:"%sagan%",Set-ItemProperty,query; meta_nocase; content:"\\Microsoft\\Windows Defender"; nocase; within:100; meta_content:"%sagan%",DisableRealtimeMonitoring,DisableAntiSpyware,DisableBehaviorMonitoring,DisableIOAVProtection,DisableIntrusionPreventionSystem,DisableInboundConnectionFiltering; meta_nocase; within:200; content:"Path: C:\\ProgramData\\Microsoft\\Windows Defender Advanced Threat Protection\\"; reference:url,github.com/mdecrevoisier/SIGMA-detection-rules/blob/main/windows-defender/defender-critical%20security%20components%20disabled%20(PowerShell).yaml; reference:url,https://bidouillesecurity.com/disable-windows-defender-in-powershell/; classtype:suspicious-command; sid:5009339; metadata: created_on 2022_11_22, old_sid 5007126; rev:3;)

Field Validations

Loading…

Comments (0)

Loading comments...