Multi-method Windows Defender exclusion for C:\ (CameraSwarm)
Detects attempts to tamper with Microsoft Windows Defender configuration, specifically by modifying exclusion paths via PowerShell cmdlets (Add-MpPreference, Set-MpPreference), direct registry modifications, or forced Group Policy updates. It also monitors for the disabling of Tamper Protection via registry and the creation of scheduled tasks designed to apply Defender exclusions.
Microsoft Sentinel (KQL)

