Windows Defender Threat Severity Default Action Modified

 Original Source: [Sigma source]
Title: Windows Defender Threat Severity Default Action Modified
Status: experimental
Description:Detects modifications or creations of Windows Defender's default threat action settings based on severity to 'allow' or take 'no action'. This is a highly suspicious configuration change that effectively disables Defender's ability to automatically mitigate threats of a certain severity level, allowing malicious software to run unimpeded. An attacker might use this technique to bypass defenses before executing payloads.
References:
  -https://learn.microsoft.com/en-us/powershell/module/defender/set-mppreference
  -https://learn.microsoft.com/en-us/windows-hardware/customize/desktop/unattend/security-malware-windows-defender-threatseveritydefaultaction
  -https://research.splunk.com/endpoint/7215831c-8252-4ae3-8d43-db588e82f952
  -https://gist.github.com/Dump-GUY/8daef859f382b895ac6fd0cf094555d2
  -https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/
Author: Matt Anderson (Huntress)
Date: 2025-07-11
modified:None
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1685'
Logsource:
  • category: registry_event
  • product: windows
Detection:
  selection:
    TargetObject|contains: '\Microsoft\Windows Defender\Threats\ThreatSeverityDefaultAction\'
    TargetObject|endswith:
      -'\1'
      -'\2'
      -'\4'
      -'\5'

    Details:
      -'DWORD (0x00000006)'
      -'DWORD (0x00000009)'

  condition:selection
Falsepositives:
  -Legitimate administration via scripts or tools (e.g., SCCM, Intune, GPO enforcement). Correlate with administrative activity.
  -Software installations that legitimately modify Defender settings (less common for these specific keys).
Level: high