Windows Process Execution: Remove Windows Defender Context Menu Registry Keys via reg.exe/PowerShell
Alerts on reg.exe/PowerShell deleting Defender context menu handler registry keys to remove right-click scanning.
- Product
- windows
- Category
- process_creation
- Author
- Matt Anderson (Huntress) (SigmaHQ), DRL 1.1
- Published
- 2025-07-09
- Updated
- 2026-07-31
ATT&CK techniques
Recon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies executions of reg.exe and PowerShell (including PowerShell ISE) that delete registry entries under the Windows shell context menu handler path for Defender. Removing these handler keys disables the "Scan with Microsoft Defender" right-click option for files, directories, and drives. Attackers may use this defense-impairment technique to reduce opportunities for on-demand scanning and lower user visibility of the security product. The detection relies on process creation telemetry, including executable path/name and command-line content indicating deletion commands and the specific registry context menu handler location.
Reporting behind it
- research.splunk.comhttps://research.splunk.com/endpoint/395ed5fe-ad13-4366-9405-a228427bdd91/
- winaero.comhttps://winaero.com/how-to-delete-scan-with-windows-defender-from-context-menu-in-windows-10/
- thedfirreport.comhttps://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/
- blog.malwarebytes.comhttps://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_defender_remove_context_menu.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Windows Process Execution: Remove Windows Defender Context Menu Registry Keys via reg.exe/PowerShell"
id: 8c66eb4f-e64d-4241-b030-1d898c48bf59
related:
- id: 72a0369a-2576-4aaf-bfc9-6bb24a574ac6
type: similar
- id: b9e8c7d6-a5f4-4e3d-8b1a-9f0c8d7e6a5b
type: derived
status: experimental
description: This rule identifies executions of reg.exe and PowerShell (including PowerShell ISE) that delete registry entries under the Windows shell context menu handler path for Defender. Removing these handler keys disables the "Scan with Microsoft Defender" right-click option for files, directories, and drives. Attackers may use this defense-impairment technique to reduce opportunities for on-demand scanning and lower user visibility of the security product. The detection relies on process creation telemetry, including executable path/name and command-line content indicating deletion commands and the specific registry context menu handler location.
references:
- https://research.splunk.com/endpoint/395ed5fe-ad13-4366-9405-a228427bdd91/
- https://winaero.com/how-to-delete-scan-with-windows-defender-from-context-menu-in-windows-10/
- https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/
- https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_defender_remove_context_menu.yml
author: Matt Anderson (Huntress), Huntrule Team
date: 2025-07-09
tags:
- attack.defense-impairment
- attack.t1685
logsource:
category: process_creation
product: windows
detection:
selection_img:
- Image|endswith:
- \powershell_ise.exe
- \powershell.exe
- \pwsh.exe
- \reg.exe
- OriginalFileName:
- powershell_ise.EXE
- PowerShell.EXE
- pwsh.dll
- reg.exe
selection_action:
CommandLine|contains:
- del
- Remove-Item
- "ri "
selection_reg_path:
CommandLine|contains: \shellex\ContextMenuHandlers\EPP
condition: all of selection_*
falsepositives:
- May be part of a system customization or "debloating" script, but this is highly unusual in a managed corporate environment.
level: high
license: DRL-1.1