Title:Disabled Windows Defender Eventlog Status:test Description:Detects the disabling of the Windows Defender eventlog as seen in relation to Lockbit 3.0 infections References: -https://twitter.com/WhichbufferArda/status/1543900539280293889/photo/2 Author: Florian Roth (Nextron Systems) Date: 2022-07-04 modified:2023-08-17 Tags:
-'attack.defense-impairment'
-'attack.t1685'
Logsource:
category: registry_set
product: windows
Detection: selection: TargetObject|contains:
'\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/Operational\Enabled' Details:
'DWORD (0x00000000)' condition:selection Falsepositives:
-Other Antivirus software installations could cause Windows to disable that eventlog (unknown) Level:high