This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Tamper Windows Defender - PSClassic
Original Source:
[Sigma source]
Title:
Tamper Windows Defender - PSClassic
Status:
test
Description:
Attempting to disable scheduled scanning and other parts of Windows Defender ATP or set default actions to allow.
References:
-https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1562.001/T1562.001.md
Author:
frack113, Nasreddine Bencherchali (Nextron Systems)
Date:
2021-06-07
modified:
2024-01-02
Tags:
-'attack.defense-impairment'
-'attack.t1685'
Logsource:
product: windows
category: ps_classic_provider_start
Detection:
selection_set_mppreference:
Data|contains
:
'Set-MpPreference'
selection_options_bool_allow:
Data|contains
:
-'-dbaf $true'
-'-dbaf 1'
-'-dbm $true'
-'-dbm 1'
-'-dips $true'
-'-dips 1'
-'-DisableArchiveScanning $true'
-'-DisableArchiveScanning 1'
-'-DisableBehaviorMonitoring $true'
-'-DisableBehaviorMonitoring 1'
-'-DisableBlockAtFirstSeen $true'
-'-DisableBlockAtFirstSeen 1'
-'-DisableCatchupFullScan $true'
-'-DisableCatchupFullScan 1'
-'-DisableCatchupQuickScan $true'
-'-DisableCatchupQuickScan 1'
-'-DisableIntrusionPreventionSystem $true'
-'-DisableIntrusionPreventionSystem 1'
-'-DisableIOAVProtection $true'
-'-DisableIOAVProtection 1'
-'-DisableRealtimeMonitoring $true'
-'-DisableRealtimeMonitoring 1'
-'-DisableRemovableDriveScanning $true'
-'-DisableRemovableDriveScanning 1'
-'-DisableScanningMappedNetworkDrivesForFullScan $true'
-'-DisableScanningMappedNetworkDrivesForFullScan 1'
-'-DisableScanningNetworkFiles $true'
-'-DisableScanningNetworkFiles 1'
-'-DisableScriptScanning $true'
-'-DisableScriptScanning 1'
-'-MAPSReporting $false'
-'-MAPSReporting 0'
-'-drdsc $true'
-'-drdsc 1'
-'-drtm $true'
-'-drtm 1'
-'-dscrptsc $true'
-'-dscrptsc 1'
-'-dsmndf $true'
-'-dsmndf 1'
-'-dsnf $true'
-'-dsnf 1'
-'-dss $true'
-'-dss 1'
selection_options_actions_func:
Data|contains
:
-'HighThreatDefaultAction Allow'
-'htdefac Allow'
-'LowThreatDefaultAction Allow'
-'ltdefac Allow'
-'ModerateThreatDefaultAction Allow'
-'mtdefac Allow'
-'SevereThreatDefaultAction Allow'
-'stdefac Allow'
condition
:
selection_set_mppreference and 1 of selection_options_*
Falsepositives:
-Legitimate PowerShell scripts that disable Windows Defender for troubleshooting purposes. Must be investigated.
Level:
high