Malicious Microsoft Defender Massive Host Infection (via windefend)

PremiumReviewedSigma · High · v1
Product
windows
Service
windefend
Author
HuntRule
Published
2026-07-20
Updated
2026-08-28

What it detects

This rule detects scenarios where multiple suspicious threats are detected on a single host.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.