Tamper Windows Defender Remove-MpPreference - ScriptBlockLogging

 Original Source: [Sigma source]
Title: Tamper Windows Defender Remove-MpPreference - ScriptBlockLogging
Status: test
Description:Detects attempts to remove Windows Defender configuration using the 'MpPreference' cmdlet
References:
  -https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/windows-10-controlled-folder-access-event-search/ba-p/2326088
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-08-05
modified:None
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1685'
Logsource:
  • product: windows
  • category: ps_script
  • definition: Requirements: Script Block Logging must be enabled
Detection:
  selection_remove:
    ScriptBlockText|contains: 'Remove-MpPreference'
  selection_tamper:
    ScriptBlockText|contains:
      -'-ControlledFolderAccessProtectedFolders '
      -'-AttackSurfaceReductionRules_Ids '
      -'-AttackSurfaceReductionRules_Actions '
      -'-CheckForSignaturesBeforeRunningScan '

  condition:all of selection_*
Falsepositives:
  -Legitimate PowerShell scripts
Level: high