Tag
high
advisory
Detection of Unauthorized Windows Defender Configuration Changes
1 ruleAdversaries frequently disable or weaken Windows Defender security features to facilitate malware persistence and execution without detection.
defense-impairment
windows
security-telemetry
1r
high
advisory
Detection of Windows Defender Real-time Protection Impairment
1 rule 1 TTPThis brief documents the detection logic for identifying when Windows Defender anti-malware scanning is disabled, a common TTP used by adversaries to impair system defenses.
defense-impairment
windows
security-telemetry
1r
1t