Skip to content

Hide Navigation Hide TOC

Powershell Base64 Encoded MpPreference Cmdlet (c6fb44c6-71f5-49e6-9462-1425d328aee3)

Detects base64 encoded "MpPreference" PowerShell cmdlet code that tries to modifies or tamper with Windows Defender AV

Cluster A Galaxy A Cluster B Galaxy B Level
Powershell Base64 Encoded MpPreference Cmdlet (c6fb44c6-71f5-49e6-9462-1425d328aee3) Sigma-Rules Disable or Modify Tools - T1562.001 (ac08589e-ee59-4935-8667-d845e38fe579) Attack Pattern 1
Disable or Modify Tools - T1562.001 (ac08589e-ee59-4935-8667-d845e38fe579) Attack Pattern Impair Defenses - T1562 (3d333250-30e4-4a82-9edc-756c68afc529) Attack Pattern 2