Suspicious Microsoft Defender Security Components Disabled - PowerShell (via powershell)

PremiumReviewedSigma · Medium · v1
Product
windows
Service
powershell
Author
HuntRule
Published
2026-08-17
Updated
2026-08-28
Full detection rule

Unlock this rule to view and copy it

The detection logic is included with a plan. Everything else — context, mappings and implementation details — stays free on this page.

Sign in for 3 free unlocks

Signing in gives you 3 unlocks to spend on any rule in the library. No card, and they do not expire.

Also included

Unlocked rules convert on this page — to Splunk SPL or Splunk — Raw Index SPL or Microsoft Sentinel KQL or Microsoft Sentinel ASIM ASIM KQL or Microsoft Defender XDR KQL or Elastic Security KQL or Elastic Security Lucene or Elastic Security ES|QL or CrowdStrike Falcon CQL or SentinelOne PowerQuery or Palo Alto Cortex XDR XQL or Carbon Black Cloud Platform Search or Carbon Black EDR Process Search or Google Security Operations UDM Search or IBM QRadar AQL or Sumo Logic Cloud SIEM Rules expression or Rapid7 InsightIDR LEQL or Graylog Search or OpenSearch Lucene or OpenSearch PPL PPL or Grafana Loki LogQL or SQLite SQL or Zircolite SQLite — with the log-source profile the engine picked, the field map it used, and everything it could not express. Converting a rule you have unlocked costs no further credit.

See it run on a free rule →Convert your own rule →