KuinaExtractor: Defender Disable via PowerShell/WMIC/sc/net (T1562.001)

Detects attempts to disable or impair Microsoft Defender Antivirus using legitimate system administration tools such as PowerShell (Set-MpPreference, Add-MpPreference), WMIC, sc.exe, or net.exe. Adversaries may use these tools to bypass security controls by disabling real-time monitoring or adding unauthorized exclusion paths.