Skip to content

Hide Navigation Hide TOC

Windows Defender Exclusion Registry Key - Write Access Requested (e9c8808f-4cfb-4ba9-97d4-e5f3beaa244d)

Detects write access requests to the Windows Defender exclusions registry keys. This could be an indication of an attacker trying to request a handle or access the object to write new exclusions in order to bypass security.

Cluster A Galaxy A Cluster B Galaxy B Level
Disable or Modify Tools - T1685 (bbde9781-60aa-4b8a-a911-895b0c1b3872) Attack Pattern Windows Defender Exclusion Registry Key - Write Access Requested (e9c8808f-4cfb-4ba9-97d4-e5f3beaa244d) Sigma-Rules 1