Windows Defender Tampering via PowerShell, sc.exe, or Registry
Detects attempts to impair Windows Defender protection by modifying preferences via PowerShell (Set-MpPreference/Add-MpPreference), stopping the WinDefend service using sc.exe, or altering sensitive Windows Defender registry keys. This rule monitors process execution and registry modification events, excluding known legitimate management tools like Intune and SCCM.
Microsoft Sentinel (KQL)

