Potential Windows Defender Tampering Via Wmic.EXE

 Original Source: [Sigma source]
Title: Potential Windows Defender Tampering Via Wmic.EXE
Status: test
Description:Detects potential tampering with Windows Defender settings such as adding exclusion using wmic
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/5c1e6f1b4fafd01c8d1ece85f510160fc1275fbf/atomics/T1562.001/T1562.001.md
  -https://www.bleepingcomputer.com/news/security/gootkit-malware-bypasses-windows-defender-by-setting-path-exclusions/
  -https://www.bleepingcomputer.com/news/security/iobit-forums-hacked-to-spread-ransomware-to-its-members/
Author: frack113
Date: 2022-12-11
modified:2023-02-14
Tags:
  • -'attack.execution'
  • -'attack.defense-impairment'
  • -'attack.t1047'
  • -'attack.t1685'
Logsource:
  • product: windows
  • category: process_creation
Detection:
  selection_img:
OriginalFileName:'wmic.exe' Image|endswith:'\WMIC.exe'   selection_cli:
    CommandLine|contains: '/Namespace:\\\\root\\Microsoft\\Windows\\Defender'
  condition:all of selection_*
Falsepositives:
  -Unknown
Level: high