Malicious Defender Tampering via UnDefend Aggressive Flag

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-09-30
Updated
2026-09-30

ATT&CK techniques

  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule detects execution of the UnDefend tool undef.exe with its -agressive flag, an EDR-tampering utility seen in a Huntress-investigated Nightmare-Eclipse intrusion that targeted the mpavbase.vdm Defender signature file. The distinctive misspelled flag identifies the specific tool used to disable endpoint protection. Disabling security controls precedes credential theft and lateral movement.

Related detections9 linkedT1685 — drag to rearrange
Suspicious Chrome Update Suppression via simulate-outdated-no-au Flag via process_creation
Suspicious Windows Defender Exclusion Added for Entire Windows Directory
Malicious ELAM Driver Disable via Bcdedit
Suspicious Windows Defender Exclusion Added via PowerShell Add-MpPreference
Suspicious Security Product Process Termination via Named Utility
Suspicious Windows Defender Disabling via SystemSettingsAdminFlows
Windows Defender Exclusion Path Added via Add-MpPreference
Suspicious Hosts File Modification to Block Security Vendors via file_event
Malicious Windows Defender Real-Time Protection Disabled via Registry
Malicious Defender Tampering via UnDefend Aggressive Flag
Pivot detection · T1685 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.