Windows Defender Service Disabled - Registry

 Original Source: [Sigma source]
Title: Windows Defender Service Disabled - Registry
Status: test
Description:Detects when an attacker or tool disables the Windows Defender service (WinDefend) via the registry
References:
  -https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/
  -https://gist.github.com/anadr/7465a9fde63d41341136949f14c21105
Author: Ján Trenčanský, frack113, AlertIQ, Nasreddine Bencherchali
Date: 2022-08-01
modified:2024-03-25
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1685'
Logsource:
  • product: windows
  • category: registry_set
Detection:
  selection:
    TargetObject|endswith: '\Services\WinDefend\Start'
    Details: 'DWORD (0x00000004)'
  condition:selection
Falsepositives:
  -Administrator actions
Level: high