• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    HEAVYGRAM PowerShell Defender Exclusion via Add-MpPreference

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ibrahim Saud@tektrix
    •updated 21 days ago•0•0•3

    Detects the use of the 'Add-MpPreference' PowerShell cmdlet with the '-ExclusionPath' parameter, which is used to add file, folder, or extension exclusions to Microsoft Defender. Attackers frequently use this technique to prevent security software from scanning or detecting malicious files or directories.

    SentinelOne

    Tags

    T1685 - Disable or Modify ToolsProcess CreationPowershell Script ExecutionProcess TamperingCommand ExecutionWindowsWindows Eventlog PowershellWindows Defender Av

    Found in

    • HEAVYGRAM Telegram Backdoor Used by Handala HackLast updated 21 days ago
    • HEAVYGRAM Telegram Backdoor Used by Handala HackLast updated 21 days ago
    • HEAVYGRAM Telegram Backdoor Used by Handala HackLast updated 21 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?