PowerShell Defender Threat Severity Default Action Set to 'Allow' or 'NoAction'

 Original Source: [Sigma source]
Title: PowerShell Defender Threat Severity Default Action Set to 'Allow' or 'NoAction'
Status: experimental
Description:Detects the use of PowerShell to execute the 'Set-MpPreference' cmdlet to configure Windows Defender's threat severity default action to 'Allow' (value '6') or 'NoAction' (value '9'). This is a highly suspicious configuration change that effectively disables Defender's ability to automatically mitigate threats of a certain severity level. An attacker might use this technique via the command line to bypass defenses before executing payloads.
References:
  -https://learn.microsoft.com/en-us/powershell/module/defender/set-mppreference
  -https://learn.microsoft.com/en-us/windows-hardware/customize/desktop/unattend/security-malware-windows-defender-threatseveritydefaultaction
  -https://research.splunk.com/endpoint/7215831c-8252-4ae3-8d43-db588e82f952
  -https://gist.github.com/Dump-GUY/8daef859f382b895ac6fd0cf094555d2
  -https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/
Author: Matt Anderson (Huntress)
Date: 2025-07-11
modified:None
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1685'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_cmdlet:
    CommandLine|contains: 'Set-MpPreference'
  selection_action:
    CommandLine|contains:
      -'-LowThreatDefaultAction'
      -'-ModerateThreatDefaultAction'
      -'-HighThreatDefaultAction'
      -'-SevereThreatDefaultAction'
      -'-ltdefac '
      -'-mtdefac '
      -'-htdefac '
      -'-stdefac '

  selection_value:
    CommandLine|contains:
      -'Allow'
      -'6'
      -'NoAction'
      -'9'

  condition:all of selection_*
Falsepositives:
  -Highly unlikely
Level: high