• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    Defender AppData Exclusion Added via PowerShell (Electron Loader)

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Arnold Chan@slaz
    •updated 26 days ago•0•0•1

    Detects the use of PowerShell commands to add directory exclusions to Windows Defender settings. Adversaries often use this technique to exclude directories in 'AppData' from being scanned by antivirus solutions to hide malicious activity, tools, or persistence mechanisms.

    Microsoft Sentinel (KQL)

    Tags

    T1685 - Disable or Modify ToolsProcess CreationCommand ExecutionPowershell Script ExecutionWindowsWindows Defender AvWindows Eventlog Powershellkql

    Found in

    • REVSTEALER Infostealer Ramps Up With Follow-on ModulesLast updated Sep 7, 2026
    • REVSTEALER: Sophisticated Infostealer with Polygon C2 ResilienceLast updated Sep 6, 2026
    • REVSTEALER: Sophisticated Infostealer with Polygon C2 ResilienceLast updated Sep 6, 2026
    • REVSTEALER: Sophisticated Infostealer with Polygon C2 ResilienceLast updated Sep 6, 2026

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?