T1687 Security/EDR/AV Process Crash Indicating Possible Exploitation
Detects unexpected crashes of major security software agents (e.g., Antivirus, EDR) that are not associated with authorized vendor update or installation activities, potentially indicating tampering or exploitation attempts to disable security controls.
Microsoft Sentinel (KQL)

