CRUDEEXCLUDE Defender Exclusion Path Configuration via PowerShell
Detects the use of PowerShell to modify Microsoft Defender (MpPreference) settings by adding specific directories or files to the exclusion list. This behavior is frequently associated with adversaries attempting to evade security detection by ensuring malicious tools, staged payloads, or persistent files remain unscanned by the antivirus engine.
Microsoft Sentinel (KQL)

