Suspicious Application Allowed Through Exploit Guard
Description
Detects applications being added to the "allowed applications" list of exploit guard in order to bypass controlled folder settings
Query · sigma
selection_key:
TargetObject|contains: SOFTWARE\Microsoft\Windows Defender\Windows Defender Exploit
Guard\Controlled Folder Access\AllowedApplications
selection_paths:
TargetObject|contains:
- \Users\Public\
- \AppData\Local\Temp\
- \Desktop\
- \PerfLogs\
- \Windows\Temp\
condition: all of selection_*
Known false positives
- Unlikely