Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0897 — Detection of Selective Exclusion
DET0897

Detection of Selective Exclusion

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN2030 Analytic 2030
Windows

A process with no prior history or outside of known whitelisted tools initiates file or registry modifications to configure exclusion rules for antivirus, backup, or file-handling systems. Or a file system enumeration for specific file names andcritical extensions like .dll, .exe, .sys, or specific directories such as 'Program Files' or security tool paths or system component discovery for the exclusion of the files or components.

WinEventLog:PowerShell EventCode=4103, 4104, 4105, 4106 WinEventLog:Security EventCode=4688 WinEventLog:Security EventCode=4663, 4670, 4656
[TimeWindow] Correlate multiply discovery activities and file enumeration activities.
[DiscoveryActivityThreshold] Minimum number of different discovery techniques within time window to trigger detection - balance between false positives and coverage (default: 4 activities)
[ExclusionTargetList] List of extensions or folders considered suspicious when excluded (e.g., .dll, .exe, C:\\Program Files\\)
[AuthorizedExclusionModifiers] Whitelist of known system management tools/processes allowed to modify exclusion settings

Detected Techniques

1

Details

MITRE ID
DET0897
STIX ID
x-mitre-detection-strategy--7c1262bb-c0d1-4e0c-bab8-a232f7bed9d5
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.