HEAVYGRAM PowerShell Defender Exclusion via Add-MpPreference
Detects the use of the 'Add-MpPreference' PowerShell cmdlet with the '-ExclusionPath' parameter, which is used to add file, folder, or extension exclusions to Microsoft Defender. Attackers frequently use this technique to prevent security software from scanning or detecting malicious files or directories.
SentinelOne

