CRUDEEXCLUDE Defender Exclusion Path via PowerShell
Detects the addition of exclusion paths to Microsoft Defender via PowerShell (Add-MpPreference or Set-MpPreference) initiated by non-Microsoft signed processes or specific messaging applications. This behavior is often indicative of malware attempting to exclude malicious payloads from security scanning.
SentinelOne

