Techniques
Sample rules
Windows Defender Disabled Via SystemSettingsAdminFlows.EXE
- source: sigma
- technicques:
- t1685
Description
Detects the usage of SystemSettingsAdminFlows.exe to disable Windows Defender. SystemSettingsAdminFlows.exe is a legitimate Windows component used for administrative configuration tasks. However, attackers may abuse it to disable Windows Defender as part of their attack chain, especially in the context of ransomware or other malware campaigns.
Detection logic
condition: all of selection_ssaf_* and (all of selection_cli_enable_* or all of selection_cli_disable_*)
selection_cli_disable_opt:
CommandLine|contains:
- 'SubmitSamplesConsent '
- 'SpyNetReporting '
- 'DisableCDPUserAuthPolicy '
selection_cli_disable_value:
CommandLine|contains: '0'
selection_cli_enable_opt:
CommandLine|contains:
- 'RTP '
- 'RealTimeProtection '
- 'DisableEnhancedNotifications '
selection_cli_enable_value:
CommandLine|contains: '1'
selection_ssaf_cli:
CommandLine|contains: defender
selection_ssaf_img:
- Image|endswith: \SystemSettingsAdminFlows.exe
- OriginalFileName: SystemSettingsAdminFlows.EXE