Disabled Windows Defender Eventlog

 Original Source: [Sigma source]
Title: Disabled Windows Defender Eventlog
Status: test
Description:Detects the disabling of the Windows Defender eventlog as seen in relation to Lockbit 3.0 infections
References:
  -https://twitter.com/WhichbufferArda/status/1543900539280293889/photo/2
Author: Florian Roth (Nextron Systems)
Date: 2022-07-04
modified:2023-08-17
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1685'
Logsource:
  • category: registry_set
  • product: windows
Detection:
  selection:
    TargetObject|contains: '\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/Operational\Enabled'
    Details: 'DWORD (0x00000000)'
  condition:selection
Falsepositives:
  -Other Antivirus software installations could cause Windows to disable that eventlog (unknown)
Level: high