Title:Windows Defender Exclusion List Modified Status:test Description:Detects modifications to the Windows Defender exclusion registry key. This could indicate a potentially suspicious or even malicious activity by an attacker trying to add a new exclusion in order to bypass security.
References: -https://www.bleepingcomputer.com/news/security/gootkit-malware-bypasses-windows-defender-by-setting-path-exclusions/ Author: @BarryShooshooga Date: 2019-10-26 modified:2023-11-11 Tags:
-'attack.defense-impairment'
-'attack.t1685'
Logsource:
product: windows
service: security
definition: Requirements: Audit Policy : Security Settings/Local Policies/Audit Policy, Registry System Access Control (SACL): Auditing/User