Defender AppData Exclusion Added via PowerShell (Electron Loader)
Detects the use of PowerShell commands to add directory exclusions to Windows Defender settings. Adversaries often use this technique to exclude directories in 'AppData' from being scanned by antivirus solutions to hide malicious activity, tools, or persistence mechanisms.
Microsoft Sentinel (KQL)

