Disabling Windows Defender WMI Autologger Session via Reg.exe

Last updated on:

In this page

About the rule

Rule Type

Standard

Rule Description

Detects use of reg.exe to disable Windows Defender ETW Autologger sessions, potentially suppressing critical security and audit events as a defense evasion technique.

Severity

Critical

Detection

Execution Mode

realtime

Log Sources

Windows

Author

@Matt Anderson (Huntress)