Windows Defender protection tampering via registry
Detects suspicious processes modifying Windows Defender configuration settings via registry to disable protection features.
- Platform: Windows
- Severity: High
- MITRE Tactic: Defense Evasion
- MITRE Techniques: T1562, T1562.001