LockAppHost adds Defender exclusions before mining (Add-MpPreference)
Detects the use of PowerShell to add Microsoft Defender exclusions (paths or extensions) where the process was initiated by or involves LockAppHost.exe. This behavior is indicative of an attempt to bypass security protections by excluding malicious artifacts from scanning.
Microsoft Sentinel (KQL)

