BitLocker Suspension and SChannel Cipher Weakening

This rule detects potentially malicious system configuration changes, specifically the suspension or disabling of BitLocker drive encryption via 'manage-bde.exe' and the weakening of SChannel security protocols or ciphers by modifying registry keys. These activities are indicative of an attacker attempting to bypass disk encryption or lower the security posture of network communication.