logo

Engineering detection around Microsoft Defender

ID: 4c83ba59-5026-5321-b7a8-56e8fdffaf67

STIX ID: report--4c83ba59-5026-5321-b7a8-56e8fdffaf67

Feed Name: Sekoia.com

Date Published: 2023-08-31

Date Updated: 2026-07-20

...
...

This blogpost reviews Microsoft Defender Antivirus (MDAV) features and common attacker techniques to disable or bypass it (registry and Set-MpPreference changes, Add-MpPreference exclusions, removing signatures via MpCmdRun, stopping Defender services, and AMSI bypasses), and provides Sigma detection rules, example commands, event IDs and notes on false positives and detection efficacy to help defenders monitor and detect tampering and evasion.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.