LoFP LoFP / seen being triggered occasionally during windows 8 defender updates

Techniques

Sample rules

Windows Defender Real-time Protection Disabled

Description

Detects disabling of Windows Defender Real-time Protection. As this event doesn’t contain a lot of information on who initaited this action you might want to reduce it to a “medium” level if this occurs too many times in your environment

Detection logic

condition: selection
selection:
  EventID: 5001