Suspicious Windows Defender Folder Exclusion Added Via Reg.EXE

 Original Source: [Sigma source]
Title: Suspicious Windows Defender Folder Exclusion Added Via Reg.EXE
Status: test
Description:Detects the usage of "reg.exe" to add Defender folder exclusions. Qbot has been seen using this technique to add exclusions for folders within AppData and ProgramData.
References:
  -https://thedfirreport.com/2022/02/07/qbot-likes-to-move-it-move-it/
  -https://redcanary.com/threat-detection-report/threats/qbot/
Author: frack113
Date: 2022-02-13
modified:2023-02-04
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1685'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    Image|endswith: '\reg.exe'
    CommandLine|contains:
      -'SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths'
      -'SOFTWARE\Microsoft\Microsoft Antimalware\Exclusions\Paths'

    CommandLine|contains|all:
      -'ADD '
      -'/t '
      -'REG_DWORD '
      -'/v '
      -'/d '
      -'0'

  condition:selection
Falsepositives:
  -Legitimate use
Level: medium