PowerShell Adds Defender Exclusions via Hidden/Elevated Window (UAC Bypass Chain
Detects the use of PowerShell with a hidden window ('-w hidden') to execute the 'Add-MpPreference' cmdlet to configure Windows Defender exclusions. This combination is often indicative of malicious activity, such as attempting to bypass security controls stealthily following a UAC bypass or initial access.
Sigma

