This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Windows Defender Exploit Guard Tamper
Original Source:
[Sigma source]
Title:
Windows Defender Exploit Guard Tamper
Status:
test
Description:
Detects when someone is adding or removing applications or folders from exploit guard "ProtectedFolders" or "AllowedApplications"
References:
-https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/windows-10-controlled-folder-access-event-search/ba-p/2326088
Author:
Nasreddine Bencherchali (Nextron Systems)
Date:
2022-08-05
modified:
2022-12-06
Tags:
-'attack.defense-impairment'
-'attack.t1685'
Logsource:
product: windows
service: windefend
Detection:
allowed_apps_key:
EventID
:
'5007'
NewValue|contains
:
'\Windows Defender\Windows Defender Exploit Guard\Controlled Folder Access\AllowedApplications\'
allowed_apps_path:
NewValue|contains
:
-'\Users\Public\'
-'\AppData\Local\Temp\'
-'\Desktop\'
-'\PerfLogs\'
-'\Windows\Temp\'
protected_folders:
EventID
:
'5007'
OldValue|contains
:
'\Windows Defender\Windows Defender Exploit Guard\Controlled Folder Access\ProtectedFolders\'
condition
:
all of allowed_apps* or protected_folders
Falsepositives:
-Unlikely
Level:
high