Microsoft Defender Tamper Protection Trigger
Description
Detects blocked attempts to change any of Defender's settings such as "Real Time Monitoring" and "Behavior Monitoring"
Query · sigma
selection: EventID: 5013 Value|endswith: - \Windows Defender\DisableAntiSpyware - \Windows Defender\DisableAntiVirus - \Windows Defender\Scan\DisableArchiveScanning - \Windows Defender\Scan\DisableScanningNetworkFiles - \Real-Time Protection\DisableRealtimeMonitoring - \Real-Time Protection\DisableBehaviorMonitoring - \Real-Time Protection\DisableIOAVProtection - \Real-Time Protection\DisableScriptScanning condition: selection
Known false positives
- Administrator might try to disable defender features during testing (must be investigated)