Rapid SYSTEM process spawn following Defender scan activity
This rule monitors for potential privilege escalation or process manipulation by identifying non-system processes that interact with or follow execution patterns associated with MsMpEng.exe (Microsoft Defender) within a short timeframe. It specifically looks for a lower-privileged process triggering an activity related to the Defender service, followed immediately by a system-privileged process on the same device, which may indicate a bypass or injection technique used to gain or abuse system permissions.
Microsoft Sentinel (KQL)

