Defender Exclusion Path Abuse by CRUDEEXCLUDE/HEAVYGRAM
This rule detects modifications to Microsoft Defender antivirus exclusions. Adversaries often add paths or files to the exclusion list to prevent the detection of malicious tools or staging folders during cyberattacks. The rule monitors both command-line execution of PowerShell (Add-MpPreference/Set-MpPreference) and direct registry modifications related to Windows Defender paths.
Splunk (SPL)

