Defender AV Exclusion Added via Registry (GPO/Native Key)
This rule detects unauthorized or suspicious modifications to Windows Defender exclusion registry keys. It monitors for registry key/value creation or set operations within Defender's exclusion paths for files or extensions. The rule evaluates the process responsible for the modification (e.g., expecting MsMpEng.exe for native keys or specific svchost.exe/gpsvc parameters for GPO keys) and flags modifications made by unauthorized processes or those involving suspicious, broad, or high-risk paths like C:\, C:\Temp, or User Public folders.
Microsoft Sentinel (KQL)

