LoFP LoFP / legitimate administrator activity restoring a file

Techniques

Sample rules

Win Defender Restored Quarantine File

Description

Detects the restoration of files from the defender quarantine

Detection logic

condition: selection
selection:
  EventID: 1009