AMSI Bypass & Security Tool Tampering (T1562.001)

This rule detects attempts to impair or disable security defenses on Windows systems. It specifically monitors for three categories of malicious behavior: PowerShell-based AMSI (Antimalware Scan Interface) bypass techniques, commands to stop security-related services (e.g., Windows Defender, SentinelOne, CrowdStrike Falcon), and the use of 'reg' or 'PowerShell' to modify registry keys associated with disabling antivirus or real-time monitoring.