Analytics BIOC
Low
✕
Disable Microsoft Defender Antivirus via registry
Disable Microsoft Defender Antivirus via registry.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Impair Defenses: Disable or Modify Tools (T1562.001)
Attacker's goals:
Adversary may attempt to disable defender antivirus to execute malicious tools and move through the network without triggering alarms.
Investigative actions:
Investigate the process that set or create the registry key.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day