PowerShell Tamper: Set-MpPreference disables Windows Defender scanning and protections

Flags PowerShell attempts to alter Windows Defender preferences using Set-MpPreference with Allow-style disable/default-action parameters.

FreeReviewedSigma · High · v2
Product
windows
Category
ps_classic_provider_start
Author
frack113, Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2021-06-07
Updated
2026-07-31
title: "PowerShell Tamper: Set-MpPreference disables Windows Defender scanning and protections"
id: dd09a83b-dde6-45b0-9a74-8cf74389ad5f
related:
  - id: 14c71865-6cd3-44ae-adaa-1db923fae5f2
    type: similar
  - id: ec19ebab-72dc-40e1-9728-4c0b805d722c
    type: derived
status: test
description: This rule identifies PowerShell activity starting a classic provider that uses Set-MpPreference to set Windows Defender settings to allow or disable multiple security features. Attackers may use these configuration changes to reduce detection and prevention coverage by turning off scanning, monitoring, and related protections or forcing default actions to allow threats. The detection relies on telemetry capturing PowerShell provider start events where the Data field contains Set-MpPreference and specific disabling or allow-related parameter values.
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1562.001/T1562.001.md
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_classic/posh_pc_tamper_windows_defender_set_mp.yml
author: frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2021-06-07
modified: 2024-01-02
tags:
  - attack.defense-impairment
  - attack.t1685
logsource:
  product: windows
  category: ps_classic_provider_start
detection:
  selection_set_mppreference:
    Data|contains: Set-MpPreference
  selection_options_bool_allow:
    Data|contains:
      - -dbaf $true
      - -dbaf 1
      - -dbm $true
      - -dbm 1
      - -dips $true
      - -dips 1
      - -DisableArchiveScanning $true
      - -DisableArchiveScanning 1
      - -DisableBehaviorMonitoring $true
      - -DisableBehaviorMonitoring 1
      - -DisableBlockAtFirstSeen $true
      - -DisableBlockAtFirstSeen 1
      - -DisableCatchupFullScan $true
      - -DisableCatchupFullScan 1
      - -DisableCatchupQuickScan $true
      - -DisableCatchupQuickScan 1
      - -DisableIntrusionPreventionSystem $true
      - -DisableIntrusionPreventionSystem 1
      - -DisableIOAVProtection $true
      - -DisableIOAVProtection 1
      - -DisableRealtimeMonitoring $true
      - -DisableRealtimeMonitoring 1
      - -DisableRemovableDriveScanning $true
      - -DisableRemovableDriveScanning 1
      - -DisableScanningMappedNetworkDrivesForFullScan $true
      - -DisableScanningMappedNetworkDrivesForFullScan 1
      - -DisableScanningNetworkFiles $true
      - -DisableScanningNetworkFiles 1
      - -DisableScriptScanning $true
      - -DisableScriptScanning 1
      - -MAPSReporting $false
      - -MAPSReporting 0
      - -drdsc $true
      - -drdsc 1
      - -drtm $true
      - -drtm 1
      - -dscrptsc $true
      - -dscrptsc 1
      - -dsmndf $true
      - -dsmndf 1
      - -dsnf $true
      - -dsnf 1
      - -dss $true
      - -dss 1
  selection_options_actions_func:
    Data|contains:
      - HighThreatDefaultAction Allow
      - htdefac Allow
      - LowThreatDefaultAction Allow
      - ltdefac Allow
      - ModerateThreatDefaultAction Allow
      - mtdefac Allow
      - SevereThreatDefaultAction Allow
      - stdefac Allow
  condition: selection_set_mppreference and 1 of selection_options_*
falsepositives:
  - Legitimate PowerShell scripts that disable Windows Defender for troubleshooting purposes. Must be investigated.
level: high
license: DRL-1.1