SOP-28: Defense Evasion / Security Tool Tampering Response

SOC analyst playbook for detecting and responding to attackers disabling Microsoft Defender, injecting AV exclusions, patching ETW, and offboarding the MDE sensor. DeviceProcessEvents, DeviceRegistryEvents, Tamper Protection alerts. KQL for Sentinel, SPL for Splunk.

2026-08-15T09:46:42.119Z
Rudra Verma, Senior Security Architect & Researcher