{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/security-hardening/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["medium"],"_cs_tags":["persistence","defense-impairment","windows","security-hardening"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eAdversaries frequently employ defense impairment techniques to reduce the visibility of malicious activity or security warnings. One such method involves modifying the Windows Registry to disable notifications from the Windows Security Center, including those related to Microsoft Defender. By setting the 'Notification_Suppress' value within the 'UX Configuration' key of the Windows Defender policies, an attacker can prevent the operating system from alerting the user or the security operations center to potential threats detected by Windows Defender. This modification is often part of a broader post-exploitation effort to maintain persistence or conduct additional malicious activities without interference from security alerts. This technique is well-documented in the Atomic Red Team framework under T1112 (Modify Registry) and serves as a critical indicator for identifying attempts to subvert endpoint security controls.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful suppression of security notifications blinds end-users to critical security events, potentially allowing malware to execute, persist, or exfiltrate data undetected by the standard Windows Defender warning system. While this does not necessarily disable the Defender scanning engine itself, it significantly degrades the security posture of the endpoint by masking active alerts.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eDeploy the provided Sigma rule to your SIEM to monitor for unauthorized modifications to the Windows Defender registry configuration.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eEnable registry object auditing via Group Policy for the 'SOFTWARE\\Policies\\Microsoft\\Windows Defender' path.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule below to detect 'Notification_Suppress' set to '1'.\u003c/li\u003e\n\u003cli\u003eInvestigate any detected registry changes for unauthorized process or user account context.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-01T12:13:57Z","date_published":"2026-09-01T12:13:57Z","id":"https://feed.craftedsignal.io/briefs/2026-09-windows-defender-suppression/","summary":"Adversaries modify Windows Registry keys to disable Windows Security Center notifications, facilitating defense impairment and persistence.","title":"Suppression of Windows Security Center Notifications","url":"https://feed.craftedsignal.io/briefs/2026-09-windows-defender-suppression/"}],"language":"en","title":"CraftedSignal Threat Feed - Security-Hardening","version":"https://jsonfeed.org/version/1.1"}