Delete Defender Scan ShellEx Context Menu Registry Key

Last updated on:

In this page

About the rule

Rule Type

Standard

Rule Description

Detects deletion of registry key that adds 'Scan with Defender' option in context menu. Attackers may use this to make it harder for users to scan files that are suspicious.

Severity

Trouble

Detection

Execution Mode

realtime

Log Sources

Windows

Author

@Matt Anderson (Huntress)