SOP-28: Defense Evasion / Security Tool Tampering Response
SOC analyst playbook for detecting and responding to attackers disabling Microsoft Defender, injecting AV exclusions, patching ETW, and offboarding the MDE sensor. DeviceProcessEvents, DeviceRegistryEvents, Tamper Protection alerts. KQL for Sentinel, SPL for Splunk.
Rudra Verma, Senior Security Architect & Researcher