DEF CON 34 – Shahak Morag – Windows Process Protection level assigned to a non-Microsoft signed process (BYOEDR pattern)
This rule detects potentially malicious attempts to modify Windows process protection levels, often used by attackers employing Bring Your Own Vulnerable Driver (BYOVD) techniques. It identifies when processes use command-line arguments like 'PsProtectedSignerAntimalware' or 'SetProcessMitigationPolicy' to assign elevated protection levels, while simultaneously ensuring the initiating process is either unsigned or not a standard executable file, which is highly indicative of suspicious activity.
Microsoft Sentinel (KQL)

