Security Tool Tampering: EDR/AV Disablement (T1562.001)
Detects attempts to disable, modify, or stop security software and endpoint protection services. The rule monitors for registry changes to Windows Defender settings, manual service management commands (sc, net) targeting security processes, and PowerShell execution using 'Set-MpPreference' to disable protection features.
CQL

