Windows Defender Real-time Protection Disabled

 Original Source: [Sigma source]
Title: Windows Defender Real-time Protection Disabled
Status: stable
Description:Detects disabling of Windows Defender Real-time Protection. As this event doesn't contain a lot of information on who initiated this action you might want to reduce it to a "medium" level if this occurs too many times in your environment
References:
  -https://learn.microsoft.com/en-us/defender-endpoint/troubleshoot-microsoft-defender-antivirus?view=o365-worldwide#event-id-5001
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1562.001/T1562.001.md
  -https://craigclouditpro.wordpress.com/2020/03/04/hunting-malicious-windows-defender-activity/
Author: Ján Trenčanský, frack113
Date: 2020-07-28
modified:2023-11-22
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1685'
Logsource:
  • product: windows
  • service: windefend
Detection:
  selection:
    EventID: '5001'
  condition:selection
Falsepositives:
  -Administrator actions (should be investigated)
  -Seen being triggered occasionally during Windows 8 Defender Updates
Level: high