PowerShell script disables Defender and excludes C:\ drive (t.ps1)
Detects the use of PowerShell to modify Microsoft Defender Antivirus configurations, specifically adding file exclusions or disabling protection features like Real-time or IOAV monitoring. These actions are common indicators of an adversary attempting to disable security controls to evade detection.
Microsoft Sentinel (KQL)

