This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
PowerShell Defender Threat Severity Default Action Set to 'Allow' or 'NoAction'
Original Source:
[Sigma source]
Title:
PowerShell Defender Threat Severity Default Action Set to 'Allow' or 'NoAction'
Status:
experimental
Description:
Detects the use of PowerShell to execute the 'Set-MpPreference' cmdlet to configure Windows Defender's threat severity default action to 'Allow' (value '6') or 'NoAction' (value '9'). This is a highly suspicious configuration change that effectively disables Defender's ability to automatically mitigate threats of a certain severity level. An attacker might use this technique via the command line to bypass defenses before executing payloads.
References:
-https://learn.microsoft.com/en-us/powershell/module/defender/set-mppreference
-https://learn.microsoft.com/en-us/windows-hardware/customize/desktop/unattend/security-malware-windows-defender-threatseveritydefaultaction
-https://research.splunk.com/endpoint/7215831c-8252-4ae3-8d43-db588e82f952
-https://gist.github.com/Dump-GUY/8daef859f382b895ac6fd0cf094555d2
-https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/
Author:
Matt Anderson (Huntress)
Date:
2025-07-11
modified:
None
Tags:
-'attack.defense-impairment'
-'attack.t1685'
Logsource:
category: process_creation
product: windows
Detection:
selection_cmdlet:
CommandLine|contains
:
'Set-MpPreference'
selection_action:
CommandLine|contains
:
-'-LowThreatDefaultAction'
-'-ModerateThreatDefaultAction'
-'-HighThreatDefaultAction'
-'-SevereThreatDefaultAction'
-'-ltdefac '
-'-mtdefac '
-'-htdefac '
-'-stdefac '
selection_value:
CommandLine|contains
:
-'Allow'
-'6'
-'NoAction'
-'9'
condition
:
all of selection_*
Falsepositives:
-Highly unlikely
Level:
high