Title:Windows Defender Exclusion Registry Key - Write Access Requested Status:test Description:Detects write access requests to the Windows Defender exclusions registry keys. This could be an indication of an attacker trying to request a handle or access the object to write new exclusions in order to bypass security.
References: -https://www.bleepingcomputer.com/news/security/gootkit-malware-bypasses-windows-defender-by-setting-path-exclusions/ Author: @BarryShooshooga, Nasreddine Bencherchali (Nextron Systems) Date: 2019-10-26 modified:2023-11-11 Tags:
-'attack.defense-impairment'
-'attack.t1685'
Logsource:
product: windows
service: security
definition: Requirements: Audit Policy : Security Settings/Local Policies/Audit Policy, Registry System Access Control (SACL): Auditing/User