PowerShell multi-method Windows Defender C:\ exclusion abuse
Detects attempts to modify Windows Defender security settings by adding exclusions to the scan path using various PowerShell cmdlets or WMI methods. This behavior is often associated with adversaries attempting to evade detection by excluding malicious tools or directories from antivirus scanning.
Splunk (SPL)

