Registry write to Defender GPO exclusion path + forced gpupdate
Detects the addition of a file path exclusion to Windows Defender via the command-line registry utility (reg.exe), followed immediately by the execution of gpupdate to force a policy refresh. This pattern is commonly used by adversaries to exclude malicious directories from security scanning and ensure the configuration change takes immediate effect.
Splunk (SPL)

