Open hieuttmmo opened 2 years ago
As mentioned in the DFIR Report, another techniques might be use to disable Defender Real-Time Protection mechanism. So in this PR, i want to use a general condition for monitor all changes in the Defender Registry Path.
FYI: Already tested this config on my home-lab and it worked great.
As mentioned in the DFIR Report, another techniques might be use to disable Defender Real-Time Protection mechanism. So in this PR, i want to use a general condition for monitor all changes in the Defender Registry Path.