Defender exclusion added for fake 'Microsoft\Windows Defender' path
Detects the addition of a Microsoft Defender exclusion path targeting suspicious directories or executables that mimic legitimate Windows Defender installation paths (e.g., 'Microsoft\Windows Defender' or 'defender.exe'). This behavior is indicative of defense evasion, allowing attackers to hide malicious files from real-time scanning by bypassing security controls via PowerShell Set-MpPreference or WMIC.
Microsoft Sentinel (KQL)

