Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0005 ✕ technique: T1685 ✕
Download CSV Show ATT&CK heatmapNew addition to Windows Defender exclusion list Low 1 variation
Windows Defender keeps the exclusion list in the registry, and any addition to it will cause it to ignore a process, path or file extension.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Hour
ATT&CK tactics: Stealth (TA0005) Defense Impairment (TA0112)ATT&CK techniques: Hide Artifacts: File/Path Exclusions (T1564.012) Disable or Modify Tools (T1685)Required data: XDR AgentAttacker's goals: Gain code execution on the host and evade security controls.Investigative actions: Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow. Check the excluded object type (process, path or extension) and nature. Check if the excluded object is malicious.Variations
New addition to Windows Defender exclusion list from an unsigned process
Medium overridden
Windows Defender keeps the exclusion list in the registry, and any addition to it will cause it to ignore a process, path or file extension. overridden