condition:selection Falsepositives:
-Legitimate administration via scripts or tools (e.g., SCCM, Intune, GPO enforcement). Correlate with administrative activity.
-Software installations that legitimately modify Defender settings (less common for these specific keys). Level:high