Microsoft Defender Tamper Protection Trigger

 Original Source: [Sigma source]
Title: Microsoft Defender Tamper Protection Trigger
Status: stable
Description:Detects blocked attempts to change any of Defender's settings such as "Real Time Monitoring" and "Behavior Monitoring"
References:
  -https://bhabeshraj.com/post/tampering-with-microsoft-defenders-tamper-protection
  -https://learn.microsoft.com/en-us/defender-endpoint/troubleshoot-microsoft-defender-antivirus?view=o365-worldwide
Author: Bhabesh Raj, Nasreddine Bencherchali
Date: 2021-07-05
modified:2022-12-06
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1685'
Logsource:
  • product: windows
  • service: windefend
Detection:
  selection:
    EventID: '5013'
    Value|endswith:
      -'\Windows Defender\DisableAntiSpyware'
      -'\Windows Defender\DisableAntiVirus'
      -'\Windows Defender\Scan\DisableArchiveScanning'
      -'\Windows Defender\Scan\DisableScanningNetworkFiles'
      -'\Real-Time Protection\DisableRealtimeMonitoring'
      -'\Real-Time Protection\DisableBehaviorMonitoring'
      -'\Real-Time Protection\DisableIOAVProtection'
      -'\Real-Time Protection\DisableScriptScanning'

  condition:selection
Falsepositives:
  -Administrator might try to disable defender features during testing (must be investigated)
Level: high