Malicious Microsoft Defender Disable via Registry by Key Group

PremiumReviewedSigma · High · v1
Product
windows
Category
registry_set
Author
HuntRule
Published
2026-10-11
Updated
2026-10-11

ATT&CK techniques

Persistence → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects registry modifications that disable Microsoft Defender antispyware or real-time monitoring, a tamper action Key Group ransomware uses to blind endpoint protection before encryption. Setting these policy values to enabled-disable is a hallmark of ransomware pre-encryption defense evasion.

Related detections9 linkedT1685 — drag to rearrange
Suspicious SmartScreen Disable via Registry Modification via registry_set
Malicious Windows Defender Service Disable via Registry
Malicious Microsoft Defender Tamper via Registry Modification
Malicious Defender Real-Time Monitoring Disable via Registry
Suspicious HrServ Registry Command Channel under IdentityStore RemoteFile (via registry_set)
Suspicious Process Made Critical via RtlSetProcessIsCritical (via ps_script)
Malicious Defender Exclusion Added for User Profile Path
Suspicious Defender Protection Disabled via Set-MpPreference
Suspicious PowerShell Decoding Base64 Payload Stored in Registry
Malicious Microsoft Defender Disable via Registry by Key Group
Pivot detection · T1685 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.