
Summary
The detection rule "Windows Impair Defense Disable Win Defender Signature Retirement" identifies modifications to the Windows registry settings that disable Windows Defender's signature retirement feature. This feature, when disabled, allows the retention of outdated antivirus signatures, potentially compromising system security by enabling attackers to evade detection mechanisms that rely on up-to-date signatures.
Categories
- Endpoint
Data Sources
- Windows Registry
- Process
- Application Log
ATT&CK Techniques
- T1562.001
- T1562
Created: 2024-11-13