Windows Registry Set to Disable Windows Defender Components

Flags registry changes that turn off Windows Defender protections via Defender and Security Center policy keys.

FreeUnreviewedSigmahighv1
title: Windows Registry Set to Disable Windows Defender Components
id: 231f806e-26eb-4cbf-87e5-7caa6ba27403
related:
  - id: a64e4198-c1c8-46a5-bc9c-324c86455fd4
    type: obsolete
  - id: fd115e64-97c7-491f-951c-fc8da7e042fa
    type: obsolete
  - id: 0eb46774-f1ab-4a74-8238-1155855f2263
    type: derived
status: test
description: This rule identifies registry value changes under Windows Defender and Windows Defender Security Center policy paths that disable specific protection features. Attackers and off-the-shelf tools may use these registry modifications to impair defensive capabilities such as real-time monitoring, scanning, behavior monitoring, and exploit/IOAV protections. It relies on registry set telemetry, matching TargetObject paths that contain Defender-related registry keys and DWORD value states indicating enable/disable outcomes, with an optional exclusion for Symantec SEP service activity.
references:
  - https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/
  - https://gist.github.com/anadr/7465a9fde63d41341136949f14c21105
  - https://admx.help/?Category=Windows_7_2008R2&Policy=Microsoft.Policies.WindowsDefender::SpyNetReporting
  - https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/ransomware-hive-conti-avoslocker
  - https://www.tenforums.com/tutorials/32236-enable-disable-microsoft-defender-pua-protection-windows-10-a.html
  - https://www.tenforums.com/tutorials/105533-enable-disable-windows-defender-exploit-protection-settings.html
  - https://www.tenforums.com/tutorials/123792-turn-off-tamper-protection-microsoft-defender-antivirus.html
  - https://securelist.com/key-group-ransomware-samples-and-telegram-schemes/114025/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_windows_defender_tamper.yml
author: AlertIQ, Ján Trenčanský, frack113, Nasreddine Bencherchali, Swachchhanda Shrawan Poudel, Huntrule Team
date: 2022-08-01
modified: 2024-10-07
tags:
  - attack.defense-impairment
  - attack.t1685
logsource:
  product: windows
  category: registry_set
detection:
  selection_main:
    TargetObject|contains:
      - \SOFTWARE\Microsoft\Windows Defender\
      - \SOFTWARE\Policies\Microsoft\Windows Defender Security Center\
      - \SOFTWARE\Policies\Microsoft\Windows Defender\
  selection_dword_1:
    TargetObject|endswith:
      - \DisableAntiSpyware
      - \DisableAntiVirus
      - \DisableBehaviorMonitoring
      - \DisableBlockAtFirstSeen
      - \DisableEnhancedNotifications
      - \DisableIntrusionPreventionSystem
      - \DisableIOAVProtection
      - \DisableOnAccessProtection
      - \DisableRealtimeMonitoring
      - \DisableScanOnRealtimeEnable
      - \DisableScriptScanning
    Details: DWORD (0x00000001)
  selection_dword_0:
    TargetObject|endswith:
      - \DisallowExploitProtectionOverride
      - \Features\TamperProtection
      - \MpEngine\MpEnablePus
      - \PUAProtection
      - \Signature Update\ForceUpdateFromMU
      - \SpyNet\SpynetReporting
      - \SpyNet\SubmitSamplesConsent
      - \Windows Defender Exploit Guard\Controlled Folder Access\EnableControlledFolderAccess
    Details: DWORD (0x00000000)
  filter_optional_symantec:
    Image|startswith: C:\Program Files\Symantec\Symantec Endpoint Protection\
    Image|endswith: \sepWscSvc64.exe
  condition: selection_main and 1 of selection_dword_* and not 1 of filter_optional_*
falsepositives:
  - Administrator actions via the Windows Defender interface
  - Third party Antivirus
level: high
license: DRL-1.1

What it detects

This rule identifies registry value changes under Windows Defender and Windows Defender Security Center policy paths that disable specific protection features. Attackers and off-the-shelf tools may use these registry modifications to impair defensive capabilities such as real-time monitoring, scanning, behavior monitoring, and exploit/IOAV protections. It relies on registry set telemetry, matching TargetObject paths that contain Defender-related registry keys and DWORD value states indicating enable/disable outcomes, with an optional exclusion for Symantec SEP service activity.

Known false positives

  • Administrator actions via the Windows Defender interface
  • Third party Antivirus

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.