Windows Defender Configuration Changes

 Original Source: [Sigma source]
Title: Windows Defender Configuration Changes
Status: stable
Description:Detects suspicious changes to the Windows Defender configuration
References:
  -https://learn.microsoft.com/en-us/defender-endpoint/troubleshoot-microsoft-defender-antivirus?view=o365-worldwide
  -https://bidouillesecurity.com/disable-windows-defender-in-powershell/#DisableAntiSpyware
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-12-06
modified:2023-11-24
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1685'
Logsource:
  • product: windows
  • service: windefend
Detection:
  selection:
    EventID: '5007'
    NewValue|contains:
      -'\Windows Defender\DisableAntiSpyware '
      -'\Windows Defender\Scan\DisableRemovableDriveScanning '
      -'\Windows Defender\Scan\DisableScanningMappedNetworkDrivesForFullScan '
      -'\Windows Defender\SpyNet\DisableBlockAtFirstSeen '
      -'\Real-Time Protection\SpyNetReporting '

  condition:selection
Falsepositives:
  -Administrator activity (must be investigated)
Level: high