Windows Defender Context Menu Removed

 Original Source: [Sigma source]
Title: Windows Defender Context Menu Removed
Status: experimental
Description:Detects the use of reg.exe or PowerShell to delete the Windows Defender context menu handler registry keys. This action removes the "Scan with Microsoft Defender" option from the right-click menu for files, directories, and drives. Attackers may use this technique to hinder manual, on-demand scans and reduce the visibility of the security product.
References:
  -https://research.splunk.com/endpoint/395ed5fe-ad13-4366-9405-a228427bdd91/
  -https://winaero.com/how-to-delete-scan-with-windows-defender-from-context-menu-in-windows-10/
  -https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/
  -https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/
Author: Matt Anderson (Huntress)
Date: 2025-07-09
modified:None
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1685'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
    - Image|endswith:
      - '\powershell_ise.exe'
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\reg.exe'
    - OriginalFileName:
      - 'powershell_ise.EXE'
      - 'PowerShell.EXE'
      - 'pwsh.dll'
      - 'reg.exe'
  selection_action:
    CommandLine|contains:
      -'del'
      -'Remove-Item'
      -'ri '

  selection_reg_path:
    CommandLine|contains: '\shellex\ContextMenuHandlers\EPP'
  condition:all of selection_*
Falsepositives:
  -May be part of a system customization or "debloating" script, but this is highly unusual in a managed corporate environment.
Level: high