Detect Commands to Disable Defender or Firewall

This rule detects command-line executions that attempt to disable Windows Defender or the Windows Firewall. It specifically looks for process creation events (EventID 4688) where the command line contains keywords like 'disable' along with 'defender' or 'firewall', executed via PowerShell or cmd. This activity is indicative of an adversary attempting to impair defenses.