CRUDEEXCLUDE Delphi Loader Adds Defender Exclusion Paths for HEAVYGRAM
This rule detects the use of the 'Add-MpPreference' PowerShell cmdlet with the '-ExclusionPath' argument to add specific file or directory paths to Microsoft Defender's exclusion list. This behavior is a common technique used by adversaries to bypass security controls by ensuring malicious tools or scripts are not scanned by Windows Defender. The rule specifically alerts on exclusions related to common staging areas or specific tools such as Telegram Desktop, SSH cache folders, and package management directories.
CQL

