Detects the outright disabling of Microsoft Defender rather than a mere exclusion: Set-MpPreference toggles that switch off real-time, behaviour, script or IOAV protection, MpCmdRun definition wipes, tamper-protection registry edits, and sc/net stop of the WinDefend, WdNisSvc or Sense services. On an SMB estate Defender is the primary control, so a kill of the engine is almost always the last defence-evasion step before a payload is dropped or ransomware detonates. The rule matched on logsource `process_creation`. Verify the event genuinely matches the described behavior, and not a known legitimate case. The rule matches on these fields — examine the exact value in the event:
Investigation queries (read-only):
Known benign causes for this rule:
The rule's references — CTI context to qualify the incident: