Windows Defender Exploit Guard Tamper

 Original Source: [Sigma source]
Title: Windows Defender Exploit Guard Tamper
Status: test
Description:Detects when someone is adding or removing applications or folders from exploit guard "ProtectedFolders" or "AllowedApplications"
References:
  -https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/windows-10-controlled-folder-access-event-search/ba-p/2326088
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-08-05
modified:2022-12-06
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1685'
Logsource:
  • product: windows
  • service: windefend
Detection:
  allowed_apps_key:
    EventID: '5007'
    NewValue|contains: '\Windows Defender\Windows Defender Exploit Guard\Controlled Folder Access\AllowedApplications\'
  allowed_apps_path:
    NewValue|contains:
      -'\Users\Public\'
      -'\AppData\Local\Temp\'
      -'\Desktop\'
      -'\PerfLogs\'
      -'\Windows\Temp\'

  protected_folders:
    EventID: '5007'
    OldValue|contains: '\Windows Defender\Windows Defender Exploit Guard\Controlled Folder Access\ProtectedFolders\'
  condition:all of allowed_apps* or protected_folders
Falsepositives:
  -Unlikely
Level: high