LoFP LoFP / some crashes can occur sometimes and the event doesn't provide enough information to tune out these cases. manual exception is required

Techniques

Sample rules

Windows Defender Real-Time Protection Failure/Restart

Description

Detects issues with Windows Defender Real-Time Protection features

Detection logic

condition: selection and not 1 of filter_optional_*
filter_optional_network_inspection:
  Feature_Name: '%%886'
  Reason:
  - '%%892'
  - '%%858'
selection:
  EventID:
  - 3002
  - 3007