Defender AV Exclusion Added via Registry - T1562.001
Detects modifications to the Windows Defender exclusion list via registry keys. Adding exclusions can be used by attackers to hide malicious files, processes, or directories from antivirus scanning.
Microsoft Sentinel (KQL)

