Windows Defender Exploit Guard Tamper
Description
Detects when someone is adding or removing applications or folders from exploit guard "ProtectedFolders" or "AllowedApplications"
Query · sigma
allowed_apps_key:
EventID: 5007
NewValue|contains: \Windows Defender\Windows Defender Exploit Guard\Controlled Folder
Access\AllowedApplications\
allowed_apps_path:
NewValue|contains:
- \Users\Public\
- \AppData\Local\Temp\
- \Desktop\
- \PerfLogs\
- \Windows\Temp\
protected_folders:
EventID: 5007
OldValue|contains: \Windows Defender\Windows Defender Exploit Guard\Controlled Folder
Access\ProtectedFolders\
condition: all of allowed_apps* or protected_folders
Known false positives
- Unlikely