Sagan critical stable other

[WINDOWS-SECURITY] Disable Windows Defender Logging

[WINDOWS-SECURITY] Disable Windows Defender Logging

View Source

Detection Logic

alert any $HOME_NET any -> $HOME_NET any (msg:"[WINDOWS-SECURITY] Disable Windows Defender Logging"; program:Security
| *Sysmon*; event_id:1,4688; meta_content:"\Control\WMI\Autologger\%sagan%",DefenderApiLogger,DefenderAuditLogger; meta_nocase; content:"REG_DWORD /d
| 22
| 0
| 22
| "; reference:url,https://thedfirreport.com/2024/08/12/threat-actors-toolkit-leveraging-sliver-poshc2-batch-scripts/; classtype:trojan-activity; sid:5015079; rev:1; metadata:deployment Endpoint, created_at 2024_08_20, updated_at 2024_08_20, mitre_tactic_id TA0008, mitre_technique_id T1071;)

Field Validations

Loading…

Comments (0)

Loading comments...