EDR/AV Tampering via Service Stop, Taskkill, or Defender Disable
Detects active attempts to disable or interfere with security products, including EDR agents and antivirus software. The rule monitors for the use of 'sc.exe' to stop or reconfigure services, 'taskkill' to terminate security-related processes, and PowerShell commands utilizing 'Set-MpPreference' to modify Windows Defender real-time protection settings. These actions are frequently observed as a precursor to ransomware deployment or other malicious activities designed to evade detection.
YARA-L

