LoFP LoFP / administrator actions (should be investigated)

Techniques

Sample rules

Windows Defender Real-time Protection Disabled

Description

Detects disabling of Windows Defender Real-time Protection. As this event doesn’t contain a lot of information on who initaited this action you might want to reduce it to a “medium” level if this occurs too many times in your environment

Detection logic

condition: selection
selection:
  EventID: 5001