CRUDEEXCLUDE Adding Defender Exclusion Paths via PowerShell
Detects the use of the Add-MpPreference cmdlet with -ExclusionPath, or processes spawned by CRUDEEXCLUDE.exe, which are associated with configuring Microsoft Defender exclusion paths. This is often used by adversaries to evade detection by excluding malicious files or directories from antivirus scanning.
Sigma

