Registry disable of Windows Defender Tamper Protection

Detects attempts to disable Windows Defender Tamper Protection via direct Registry modification or by executing PowerShell commands. Disabling Tamper Protection is a common tactic used by adversaries to facilitate further malicious activity, such as impairing security controls or deleting malware artifacts without interference from Windows Defender.