• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    Windows Defender Real-Time Protection Disabled via PowerShell

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ankit Mehta@Secvyn
    •updated Jun 29, 2026•0•0•1

    Detects the use of PowerShell to modify Microsoft Defender preferences, specifically attempting to disable security features like Realtime Monitoring, IOAV protection, or Behavior Monitoring.

    SentinelOne

    Tags

    T1562.001 - Disable or Modify ToolsT1059.001 - PowerShellTA0005 - Defense EvasionTA0002 - ExecutionProcess CreationProcess TamperingCommand ExecutionPowershell Script ExecutionWindowsWindows Eventlog PowershellWindows Defender Av

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?