Suspicious Windows Defender Registry Key Tampering Via Reg.EXE — Detection Rule

Detects the usage of "reg.exe" to tamper with different Windows Defender registry keys in order to disable some important features related to protection and detection

Read the full analysis on IntelFusions