PowerShell Tampering with Windows Defender via Set-MpPreference Allow Options

Flags PowerShell attempts to alter Windows Defender preferences using Set-MpPreference with Allow-style disable/default-action parameters.

FreeUnreviewedSigmahighv1
title: PowerShell Tampering with Windows Defender via Set-MpPreference Allow Options
id: dd09a83b-dde6-45b0-9a74-8cf74389ad5f
related:
  - id: 14c71865-6cd3-44ae-adaa-1db923fae5f2
    type: similar
  - id: ec19ebab-72dc-40e1-9728-4c0b805d722c
    type: derived
status: test
description: This rule identifies PowerShell Classic provider activity that includes a Set-MpPreference command and parameters or default-action settings that effectively allow potentially malicious scanning/detection behaviors to be weakened or disabled. Attackers may use these configuration changes to impair Windows Defender protections, reduce visibility, or permit threats to run with less interference. The detection relies on PowerShell command-line or script content containing Set-MpPreference along with specific parameter values and “DefaultAction Allow” strings.
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1562.001/T1562.001.md
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_classic/posh_pc_tamper_windows_defender_set_mp.yml
author: frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2021-06-07
modified: 2024-01-02
tags:
  - attack.defense-impairment
  - attack.t1685
logsource:
  product: windows
  category: ps_classic_provider_start
detection:
  selection_set_mppreference:
    Data|contains: Set-MpPreference
  selection_options_bool_allow:
    Data|contains:
      - -dbaf $true
      - -dbaf 1
      - -dbm $true
      - -dbm 1
      - -dips $true
      - -dips 1
      - -DisableArchiveScanning $true
      - -DisableArchiveScanning 1
      - -DisableBehaviorMonitoring $true
      - -DisableBehaviorMonitoring 1
      - -DisableBlockAtFirstSeen $true
      - -DisableBlockAtFirstSeen 1
      - -DisableCatchupFullScan $true
      - -DisableCatchupFullScan 1
      - -DisableCatchupQuickScan $true
      - -DisableCatchupQuickScan 1
      - -DisableIntrusionPreventionSystem $true
      - -DisableIntrusionPreventionSystem 1
      - -DisableIOAVProtection $true
      - -DisableIOAVProtection 1
      - -DisableRealtimeMonitoring $true
      - -DisableRealtimeMonitoring 1
      - -DisableRemovableDriveScanning $true
      - -DisableRemovableDriveScanning 1
      - -DisableScanningMappedNetworkDrivesForFullScan $true
      - -DisableScanningMappedNetworkDrivesForFullScan 1
      - -DisableScanningNetworkFiles $true
      - -DisableScanningNetworkFiles 1
      - -DisableScriptScanning $true
      - -DisableScriptScanning 1
      - -MAPSReporting $false
      - -MAPSReporting 0
      - -drdsc $true
      - -drdsc 1
      - -drtm $true
      - -drtm 1
      - -dscrptsc $true
      - -dscrptsc 1
      - -dsmndf $true
      - -dsmndf 1
      - -dsnf $true
      - -dsnf 1
      - -dss $true
      - -dss 1
  selection_options_actions_func:
    Data|contains:
      - HighThreatDefaultAction Allow
      - htdefac Allow
      - LowThreatDefaultAction Allow
      - ltdefac Allow
      - ModerateThreatDefaultAction Allow
      - mtdefac Allow
      - SevereThreatDefaultAction Allow
      - stdefac Allow
  condition: selection_set_mppreference and 1 of selection_options_*
falsepositives:
  - Legitimate PowerShell scripts that disable Windows Defender for troubleshooting purposes. Must be investigated.
level: high
license: DRL-1.1

What it detects

This rule identifies PowerShell Classic provider activity that includes a Set-MpPreference command and parameters or default-action settings that effectively allow potentially malicious scanning/detection behaviors to be weakened or disabled. Attackers may use these configuration changes to impair Windows Defender protections, reduce visibility, or permit threats to run with less interference. The detection relies on PowerShell command-line or script content containing Set-MpPreference along with specific parameter values and “DefaultAction Allow” strings.

Known false positives

  • Legitimate PowerShell scripts that disable Windows Defender for troubleshooting purposes. Must be investigated.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.