High Frequency of Security Tool Command-Line Activity
This rule detects a high frequency (3 or more within an hour) of command-line executions containing keywords like 'antivirus', 'defense', or 'endpoint' on a Windows system. This activity could indicate an adversary attempting to interact with, disable, or tamper with security software to evade detection.
Microsoft Sentinel (KQL)

