For the complete documentation index, see llms.txt. This page is also available as Markdown.

Disable Microsoft Defender Antivirus via registry

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent with eXtended Threat Hunting (XTH)

ATT&CK Tactic

Defense Impairment (TA0112)

ATT&CK Technique

Disable or Modify Tools (T1685)

Severity

Low

Description

Disable Microsoft Defender Antivirus via registry.

Attacker's Goals

  • Adversary may attempt to disable defender antivirus to execute malicious tools and move through the network without triggering alarms.

Investigative actions

  • Investigate the process that set or create the registry key.

Was this helpful?