Suspicious Windows Defender Folder Exclusion Added Via Reg.EXE — Detection Rule

Detects the usage of "reg.exe" to add Defender folder exclusions. Qbot has been seen using this technique to add exclusions for folders within AppData and ProgramData.

Read the full analysis on IntelFusions