Windows registry delete: remove ShellEx ContextMenuHandlers EPP key for "Scan with Defender"

Alerts when a registry key tied to the Defender “Scan with” context menu is deleted, excluding MsMpEng.exe activity.

FreeReviewedSigma · Medium · v1
Product
windows
Category
registry_delete
Author
Matt Anderson (Huntress) (SigmaHQ), DRL 1.1
Published
2025-07-11
Updated
2026-07-30

What it detects

This rule identifies deletion of a Windows registry key under ShellEx ContextMenuHandlers with an EPP-related path, which is associated with the "Scan with Defender" context menu option. Attackers can impair endpoint defenses by removing user-accessible scanning functionality. The rule relies on Windows registry delete events and correlates them with the deleting process image path, excluding cases where the activity is attributed to MsMpEng.exe from common Windows Defender locations.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.