This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Windows Defender Service Disabled - Registry
Original Source:
[Sigma source]
Title:
Windows Defender Service Disabled - Registry
Status:
test
Description:
Detects when an attacker or tool disables the Windows Defender service (WinDefend) via the registry
References:
-https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/
-https://gist.github.com/anadr/7465a9fde63d41341136949f14c21105
Author:
Ján Trenčanský, frack113, AlertIQ, Nasreddine Bencherchali
Date:
2022-08-01
modified:
2024-03-25
Tags:
-'attack.defense-impairment'
-'attack.t1685'
Logsource:
product: windows
category: registry_set
Detection:
selection:
TargetObject|endswith
:
'\Services\WinDefend\Start'
Details
:
'DWORD (0x00000004)'
condition
:
selection
Falsepositives:
-Administrator actions
Level:
high