Windows Process Execution: Remove Windows Defender Context Menu Registry Keys via reg.exe/PowerShell

Alerts on reg.exe/PowerShell deleting Defender context menu handler registry keys to remove right-click scanning.

FreeReviewedSigma · High · v2
Product
windows
Category
process_creation
Author
Matt Anderson (Huntress) (SigmaHQ), DRL 1.1
Published
2025-07-09
Updated
2026-07-31
title: "Windows Process Execution: Remove Windows Defender Context Menu Registry Keys via reg.exe/PowerShell"
id: 8c66eb4f-e64d-4241-b030-1d898c48bf59
related:
  - id: 72a0369a-2576-4aaf-bfc9-6bb24a574ac6
    type: similar
  - id: b9e8c7d6-a5f4-4e3d-8b1a-9f0c8d7e6a5b
    type: derived
status: experimental
description: This rule identifies executions of reg.exe and PowerShell (including PowerShell ISE) that delete registry entries under the Windows shell context menu handler path for Defender. Removing these handler keys disables the "Scan with Microsoft Defender" right-click option for files, directories, and drives. Attackers may use this defense-impairment technique to reduce opportunities for on-demand scanning and lower user visibility of the security product. The detection relies on process creation telemetry, including executable path/name and command-line content indicating deletion commands and the specific registry context menu handler location.
references:
  - https://research.splunk.com/endpoint/395ed5fe-ad13-4366-9405-a228427bdd91/
  - https://winaero.com/how-to-delete-scan-with-windows-defender-from-context-menu-in-windows-10/
  - https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/
  - https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_defender_remove_context_menu.yml
author: Matt Anderson (Huntress), Huntrule Team
date: 2025-07-09
tags:
  - attack.defense-impairment
  - attack.t1685
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    - Image|endswith:
        - \powershell_ise.exe
        - \powershell.exe
        - \pwsh.exe
        - \reg.exe
    - OriginalFileName:
        - powershell_ise.EXE
        - PowerShell.EXE
        - pwsh.dll
        - reg.exe
  selection_action:
    CommandLine|contains:
      - del
      - Remove-Item
      - "ri "
  selection_reg_path:
    CommandLine|contains: \shellex\ContextMenuHandlers\EPP
  condition: all of selection_*
falsepositives:
  - May be part of a system customization or "debloating" script, but this is highly unusual in a managed corporate environment.
level: high
license: DRL-1.1