Product
high
advisory
Potential Disabling of Windows Defender Antivirus via Registry Modification
2 rules 1 TTPAn attacker might attempt to disable Windows Defender Antivirus by modifying specific registry keys, potentially leading to a system vulnerable to malware and other threats.
Windows Defender Antivirus
windowsdefender
registry
antivirus
disable
malware
2r
1t
medium
advisory
MpCmdRun Used for Remote File Download
2 rules 1 TTPAttackers are abusing the Windows Defender command-line utility, MpCmdRun.exe, to download malicious files from remote URLs, enabling them to introduce malware or offensive tooling into compromised environments.
Windows Defender Antivirus
living-off-the-land
file-download
windows
2r
1t