BitLocker Suspension and SChannel Cipher Weakening
This rule detects potentially malicious system configuration changes, specifically the suspension or disabling of BitLocker drive encryption via 'manage-bde.exe' and the weakening of SChannel security protocols or ciphers by modifying registry keys. These activities are indicative of an attacker attempting to bypass disk encryption or lower the security posture of network communication.
Microsoft Sentinel (KQL)

