T1562.001 Impair Defenses Disable or Modify Tools Defender Disabling or Exclusions
T1562.001 - Impair Defenses: Disable or Modify Tools - Defender Disabling or Exclusions¶
DESCRIPTION¶
This query detects attempts to disable defender or it detects attempts to add exclusions.
Example:
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe” Set-MpPreference -ExclusionPath ‘C:\’
Related
Malware, Ransomware
Reference:
https://github.com/SigmaHQ/sigma/blob/8d28609c041867e1cea7821900e43c0106e6c766/rules/windows/process_creation/proc_creation_win_powershell_defender_exclusion.yml#L24
ATT&CK TACTICS¶
T1562.001 - Impair Defenses: Disable or Modify Tools
Data Source(s): Command
SENTINEL RULE QUERY¶
Triage¶
- Inspect if the activities were expected and approved. It may be performed by an admin or part of service installation
- Validate the initiating process, and location of the executables.
FalsePositive¶
- Jetbrains excluding itself from Defender during installation process.
VERSION¶
Version 2.0 (date: 08/02/2024)