Skip to content

Update proc_creation_win_reg_windows_defender_tamper.yml#5148

Merged
phantinuss merged 2 commits intoSigmaHQ:masterfrom
MalGamy12:patch-12
Jun 11, 2025
Merged

Update proc_creation_win_reg_windows_defender_tamper.yml#5148
phantinuss merged 2 commits intoSigmaHQ:masterfrom
MalGamy12:patch-12

Conversation

@MalGamy12
Copy link
Copy Markdown
Contributor

@MalGamy12 MalGamy12 commented Dec 31, 2024

Summary of the Pull Request

Add new values which used by the attacker to disable windows defender

Changelog

update: Suspicious Windows Defender Registry Key Tampering Via Reg.EXE - Increase coverage by adding new values that allow for Windows Defender to be disabled such as DisableCloudProtection and DisableSecurityCenter

Example Log Event

Fixed Issues

SigmaHQ Rule Creation Conventions

  • If your PR adds new rules, please consider following and applying these conventions

@github-actions github-actions Bot added Rules Windows Pull request add/update windows related rules labels Dec 31, 2024
frack113
frack113 previously approved these changes Jan 1, 2025
Comment thread rules/windows/process_creation/proc_creation_win_reg_windows_defender_tamper.yml Outdated
@nasbench nasbench dismissed frack113’s stale review January 6, 2025 14:43

The author of the PR did not provide enough data for an approval yet.

@nasbench nasbench added Author Input Required changes the require information from original author of the rules Work In Progress Some changes are needed and removed 2nd Review Needed labels Jan 6, 2025
@nasbench nasbench marked this pull request as draft January 30, 2025 20:31
@nasbench nasbench marked this pull request as ready for review June 4, 2025 16:32
@nasbench nasbench added Ready to Merge and removed Work In Progress Some changes are needed Author Input Required changes the require information from original author of the rules labels Jun 4, 2025
@nasbench nasbench added this to the Sigma-March-April-Release milestone Jun 4, 2025
@nasbench nasbench requested a review from phantinuss June 4, 2025 16:34
@phantinuss phantinuss merged commit dfc7f6c into SigmaHQ:master Jun 11, 2025
12 checks passed
phantinuss pushed a commit that referenced this pull request Jun 11, 2025
…egistry Key Tampering Via Reg.EXE

update: Suspicious Windows Defender Registry Key Tampering Via Reg.EXE - Increase coverage by adding new values that allow for Windows Defender to be disabled such as DisableCloudProtection and DisableSecurityCenter

---------

Co-authored-by: Nasreddine Bencherchali <monsteroffire2@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Ready to Merge Rules Windows Pull request add/update windows related rules

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants