{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/security-telemetry/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["high"],"_cs_tags":["defense-impairment","windows","security-telemetry"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eAttackers often target Windows Defender Antivirus configuration settings to impair host-based security controls. By modifying specific registry keys, adversaries can disable real-time protection, bypass signature-based detection, or exclude malicious directories from scans. This activity is commonly observed during the defense evasion stage of an attack, often performed via PowerShell scripts or direct registry modifications. Monitoring Windows Defender operational logs is critical for defenders to identify unauthorized modifications that deviate from baseline organizational policy. Defenders should focus on Event ID 5007 within the Windows Defender service logs, which records changes to antimalware platform configurations, to identify potential tampering attempts.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful modification of Windows Defender configuration leads to the disabling of essential security features, leaving the host vulnerable to malware execution, credential theft, and persistent unauthorized access. This allows adversaries to maintain a foothold on the target system while evading automated security analysis and behavioral detection mechanisms.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the provided Sigma rule to monitor Windows Defender event logs for configuration tampering.\u003c/li\u003e\n\u003cli\u003eEnable Sysmon or Windows Event Log collection for Event ID 5007 on all critical endpoints.\u003c/li\u003e\n\u003cli\u003eInvestigate any alerts generated by this rule, as legitimate administrative changes should be documented and authorized through a change management process.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-01T13:09:41Z","date_published":"2026-09-01T13:09:41Z","id":"https://feed.craftedsignal.io/briefs/2026-09-windows-defender-tampering/","summary":"Adversaries frequently disable or weaken Windows Defender security features to facilitate malware persistence and execution without detection.","title":"Detection of Unauthorized Windows Defender Configuration Changes","url":"https://feed.craftedsignal.io/briefs/2026-09-windows-defender-tampering/"},{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["high"],"_cs_tags":["defense-impairment","windows","security-telemetry"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eAdversaries often attempt to disable security software to facilitate the deployment of malware, ransomware, or persistence mechanisms without triggering heuristic or signature-based alerts. Disabling Windows Defender specifically allows attackers to move laterally, execute malicious payloads, or establish command-and-control communication with reduced risk of detection. Monitoring for the deactivation of antivirus features is a critical component of a robust defense-in-depth strategy. This brief focuses on detecting Microsoft-Windows-Windows Defender Event ID 5012, which indicates that the scanning engine has been turned off. This event is typically generated following administrative actions or malicious modifications to Windows registry keys and security settings. Detection engineers should ensure that these events are forwarded to their security information and event management (SIEM) systems to alert on unauthorized changes to anti-malware configurations.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful impairment of Windows Defender significantly lowers the security posture of an endpoint, rendering the system vulnerable to a wide range of exploits and malicious payloads that would otherwise be blocked. If the feature is disabled, attackers can perform post-exploitation activities, including credential dumping, persistence installation, and data exfiltration, with a much higher probability of evading detection. This technique is frequently observed across various campaigns targeting Windows environments to ensure persistent access and stealthy execution.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eEnable collection of Microsoft-Windows-Windows Defender/Operational logs in all Windows endpoints.\u003c/li\u003e\n\u003cli\u003eImplement the provided Sigma rule to alert on Event ID 5012, which signifies a high-severity security configuration change.\u003c/li\u003e\n\u003cli\u003eInvestigate the source of any Event ID 5012 to determine if it resulted from authorized system administration or unauthorized malicious activity.\u003c/li\u003e\n\u003cli\u003eEstablish a baseline of authorized software deployment and maintenance activities to tune out expected occurrences of antivirus service configuration changes.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-01T12:07:48Z","date_published":"2026-09-01T12:07:48Z","id":"https://feed.craftedsignal.io/briefs/2026-09-windows-defender-disabled/","summary":"This brief documents the detection logic for identifying when Windows Defender anti-malware scanning is disabled, a common TTP used by adversaries to impair system defenses.","title":"Detection of Windows Defender Real-time Protection Impairment","url":"https://feed.craftedsignal.io/briefs/2026-09-windows-defender-disabled/"}],"language":"en","title":"CraftedSignal Threat Feed - Security-Telemetry","version":"https://jsonfeed.org/version/1.1"}