Suspicious Application Allowed Through Exploit Guard

 Original Source: [Sigma source]
Title: Suspicious Application Allowed Through Exploit Guard
Status: test
Description:Detects applications being added to the "allowed applications" list of exploit guard in order to bypass controlled folder settings
References:
  -https://www.microsoft.com/security/blog/2017/10/23/windows-defender-exploit-guard-reduce-the-attack-surface-against-next-generation-malware/
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-08-05
modified:2023-08-17
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1685'
Logsource:
  • category: registry_set
  • product: windows
Detection:
  selection_key:
    TargetObject|contains: 'SOFTWARE\Microsoft\Windows Defender\Windows Defender Exploit Guard\Controlled Folder Access\AllowedApplications'
  selection_paths:
    TargetObject|contains:
      -'\Users\Public\'
      -'\AppData\Local\Temp\'
      -'\Desktop\'
      -'\PerfLogs\'
      -'\Windows\Temp\'

  condition:all of selection_*
Falsepositives:
  -Unlikely
Level: high