Windows Registry Set to Disable Windows Defender Components
Flags registry changes that turn off Windows Defender protections via Defender and Security Center policy keys.
- Product
- windows
- Category
- registry_set
- Author
- AlertIQ, Ján Trenčanský, frack113, Nasreddine Bencherchali, Swachchhanda Shrawan Poudel (SigmaHQ), DRL 1.1
- Published
- 2022-08-01
- Updated
- 2026-07-30
ATT&CK techniques
Recon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies registry value changes under Windows Defender and Windows Defender Security Center policy paths that disable specific protection features. Attackers and off-the-shelf tools may use these registry modifications to impair defensive capabilities such as real-time monitoring, scanning, behavior monitoring, and exploit/IOAV protections. It relies on registry set telemetry, matching TargetObject paths that contain Defender-related registry keys and DWORD value states indicating enable/disable outcomes, with an optional exclusion for Symantec SEP service activity.
Reporting behind it
- thedfirreport.comhttps://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/
- gist.github.comhttps://gist.github.com/anadr/7465a9fde63d41341136949f14c21105
- admx.helphttps://admx.help/?Category=Windows_7_2008R2&Policy=Microsoft.Policies.WindowsDefender::SpyNetReporting
- symantec-enterprise-blogs.security.comhttps://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/ransomware-hive-conti-avoslocker
- tenforums.comhttps://www.tenforums.com/tutorials/32236-enable-disable-microsoft-defender-pua-protection-windows-10-a.html
- tenforums.comhttps://www.tenforums.com/tutorials/105533-enable-disable-windows-defender-exploit-protection-settings.html
- tenforums.comhttps://www.tenforums.com/tutorials/123792-turn-off-tamper-protection-microsoft-defender-antivirus.html
- securelist.comhttps://securelist.com/key-group-ransomware-samples-and-telegram-schemes/114025/
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_windows_defender_tamper.yml
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows Registry Set to Disable Windows Defender Components
id: 231f806e-26eb-4cbf-87e5-7caa6ba27403
related:
- id: a64e4198-c1c8-46a5-bc9c-324c86455fd4
type: obsolete
- id: fd115e64-97c7-491f-951c-fc8da7e042fa
type: obsolete
- id: 0eb46774-f1ab-4a74-8238-1155855f2263
type: derived
status: test
description: This rule identifies registry value changes under Windows Defender and Windows Defender Security Center policy paths that disable specific protection features. Attackers and off-the-shelf tools may use these registry modifications to impair defensive capabilities such as real-time monitoring, scanning, behavior monitoring, and exploit/IOAV protections. It relies on registry set telemetry, matching TargetObject paths that contain Defender-related registry keys and DWORD value states indicating enable/disable outcomes, with an optional exclusion for Symantec SEP service activity.
references:
- https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/
- https://gist.github.com/anadr/7465a9fde63d41341136949f14c21105
- https://admx.help/?Category=Windows_7_2008R2&Policy=Microsoft.Policies.WindowsDefender::SpyNetReporting
- https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/ransomware-hive-conti-avoslocker
- https://www.tenforums.com/tutorials/32236-enable-disable-microsoft-defender-pua-protection-windows-10-a.html
- https://www.tenforums.com/tutorials/105533-enable-disable-windows-defender-exploit-protection-settings.html
- https://www.tenforums.com/tutorials/123792-turn-off-tamper-protection-microsoft-defender-antivirus.html
- https://securelist.com/key-group-ransomware-samples-and-telegram-schemes/114025/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_windows_defender_tamper.yml
author: AlertIQ, Ján Trenčanský, frack113, Nasreddine Bencherchali, Swachchhanda Shrawan Poudel, Huntrule Team
date: 2022-08-01
modified: 2024-10-07
tags:
- attack.defense-impairment
- attack.t1685
logsource:
product: windows
category: registry_set
detection:
selection_main:
TargetObject|contains:
- \SOFTWARE\Microsoft\Windows Defender\
- \SOFTWARE\Policies\Microsoft\Windows Defender Security Center\
- \SOFTWARE\Policies\Microsoft\Windows Defender\
selection_dword_1:
TargetObject|endswith:
- \DisableAntiSpyware
- \DisableAntiVirus
- \DisableBehaviorMonitoring
- \DisableBlockAtFirstSeen
- \DisableEnhancedNotifications
- \DisableIntrusionPreventionSystem
- \DisableIOAVProtection
- \DisableOnAccessProtection
- \DisableRealtimeMonitoring
- \DisableScanOnRealtimeEnable
- \DisableScriptScanning
Details: DWORD (0x00000001)
selection_dword_0:
TargetObject|endswith:
- \DisallowExploitProtectionOverride
- \Features\TamperProtection
- \MpEngine\MpEnablePus
- \PUAProtection
- \Signature Update\ForceUpdateFromMU
- \SpyNet\SpynetReporting
- \SpyNet\SubmitSamplesConsent
- \Windows Defender Exploit Guard\Controlled Folder Access\EnableControlledFolderAccess
Details: DWORD (0x00000000)
filter_optional_symantec:
Image|startswith: C:\Program Files\Symantec\Symantec Endpoint Protection\
Image|endswith: \sepWscSvc64.exe
condition: selection_main and 1 of selection_dword_* and not 1 of filter_optional_*
falsepositives:
- Administrator actions via the Windows Defender interface
- Third party Antivirus
level: high
license: DRL-1.1