Malicious Windows Defender Service Disable via Registry

PremiumReviewedSigma · High · v1
Product
windows
Category
registry_set
Author
HuntRule
Published
2026-10-01
Updated
2026-10-01

ATT&CK techniques

Persistence → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects the WinDefend service Start value being set to 4 (disabled) in the registry, preventing Microsoft Defender from launching at boot. This defense-evasion step appears in recurring ransomware playbooks that neutralize endpoint protection before encryption. Disabling the AV service removes real-time protection across reboots.

Related detections9 linkedT1112 — drag to rearrange
Malicious Microsoft Defender Tamper via Registry Modification
Malicious Defender Real-Time Monitoring Disable via Registry
Suspicious Windows Defender or Firewall Service Disabled via Registry
Malicious Restricted Admin Mode Enabled for Pass-the-Hash RDP
Suspicious RDP Enablement via fDenyTSConnections Registry Modification
LanmanServer MaxMpxCt Registry Modification for Lateral Movement Preparation
Malicious WDigest UseLogonCredential Enablement for Cleartext Credentials
Suspicious WMI Event Consumer Creation for MbRemoval Persistence via ps_script
Malicious Defender Exclusion Addition via Add-MpPreference
Malicious Windows Defender Service Disable via Registry
Pivot detection · T1112 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.