Powershell Defender Exclusion

 Original Source: [Sigma source]
Title: Powershell Defender Exclusion
Status: test
Description:Detects requests to exclude files, folders or processes from Antivirus scanning using PowerShell cmdlets
References:
  -https://learn.microsoft.com/en-us/defender-endpoint/configure-process-opened-file-exclusions-microsoft-defender-antivirus
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1562.001/T1562.001.md
  -https://twitter.com/AdamTheAnalyst/status/1483497517119590403
Author: Florian Roth (Nextron Systems)
Date: 2021-04-29
modified:2022-05-12
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1685'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection1:
    CommandLine|contains:
      -'Add-MpPreference '
      -'Set-MpPreference '

  selection2:
    CommandLine|contains:
      -' -ExclusionPath '
      -' -ExclusionExtension '
      -' -ExclusionProcess '
      -' -ExclusionIpAddress '

  condition:all of selection*
Falsepositives:
  -Possible Admin Activity
  -Other Cmdlets that may use the same parameters
Level: medium