PowerShell Tamper: Set-MpPreference disables Windows Defender scanning and protections
Flags PowerShell attempts to alter Windows Defender preferences using Set-MpPreference with Allow-style disable/default-action parameters.
- Product
- windows
- Category
- ps_classic_provider_start
- Author
- frack113, Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2021-06-07
- Updated
- 2026-07-31
ATT&CK techniques
Recon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies PowerShell activity starting a classic provider that uses Set-MpPreference to set Windows Defender settings to allow or disable multiple security features. Attackers may use these configuration changes to reduce detection and prevention coverage by turning off scanning, monitoring, and related protections or forcing default actions to allow threats. The detection relies on telemetry capturing PowerShell provider start events where the Data field contains Set-MpPreference and specific disabling or allow-related parameter values.
Reporting behind it
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "PowerShell Tamper: Set-MpPreference disables Windows Defender scanning and protections"
id: dd09a83b-dde6-45b0-9a74-8cf74389ad5f
related:
- id: 14c71865-6cd3-44ae-adaa-1db923fae5f2
type: similar
- id: ec19ebab-72dc-40e1-9728-4c0b805d722c
type: derived
status: test
description: This rule identifies PowerShell activity starting a classic provider that uses Set-MpPreference to set Windows Defender settings to allow or disable multiple security features. Attackers may use these configuration changes to reduce detection and prevention coverage by turning off scanning, monitoring, and related protections or forcing default actions to allow threats. The detection relies on telemetry capturing PowerShell provider start events where the Data field contains Set-MpPreference and specific disabling or allow-related parameter values.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1562.001/T1562.001.md
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_classic/posh_pc_tamper_windows_defender_set_mp.yml
author: frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2021-06-07
modified: 2024-01-02
tags:
- attack.defense-impairment
- attack.t1685
logsource:
product: windows
category: ps_classic_provider_start
detection:
selection_set_mppreference:
Data|contains: Set-MpPreference
selection_options_bool_allow:
Data|contains:
- -dbaf $true
- -dbaf 1
- -dbm $true
- -dbm 1
- -dips $true
- -dips 1
- -DisableArchiveScanning $true
- -DisableArchiveScanning 1
- -DisableBehaviorMonitoring $true
- -DisableBehaviorMonitoring 1
- -DisableBlockAtFirstSeen $true
- -DisableBlockAtFirstSeen 1
- -DisableCatchupFullScan $true
- -DisableCatchupFullScan 1
- -DisableCatchupQuickScan $true
- -DisableCatchupQuickScan 1
- -DisableIntrusionPreventionSystem $true
- -DisableIntrusionPreventionSystem 1
- -DisableIOAVProtection $true
- -DisableIOAVProtection 1
- -DisableRealtimeMonitoring $true
- -DisableRealtimeMonitoring 1
- -DisableRemovableDriveScanning $true
- -DisableRemovableDriveScanning 1
- -DisableScanningMappedNetworkDrivesForFullScan $true
- -DisableScanningMappedNetworkDrivesForFullScan 1
- -DisableScanningNetworkFiles $true
- -DisableScanningNetworkFiles 1
- -DisableScriptScanning $true
- -DisableScriptScanning 1
- -MAPSReporting $false
- -MAPSReporting 0
- -drdsc $true
- -drdsc 1
- -drtm $true
- -drtm 1
- -dscrptsc $true
- -dscrptsc 1
- -dsmndf $true
- -dsmndf 1
- -dsnf $true
- -dsnf 1
- -dss $true
- -dss 1
selection_options_actions_func:
Data|contains:
- HighThreatDefaultAction Allow
- htdefac Allow
- LowThreatDefaultAction Allow
- ltdefac Allow
- ModerateThreatDefaultAction Allow
- mtdefac Allow
- SevereThreatDefaultAction Allow
- stdefac Allow
condition: selection_set_mppreference and 1 of selection_options_*
falsepositives:
- Legitimate PowerShell scripts that disable Windows Defender for troubleshooting purposes. Must be investigated.
level: high
license: DRL-1.1