Tamper protection
The MITRE ATT&CK tactic of defense evasion is one seen frequently in security incidents. This tactic refers to all techniques that avoid, disable, or otherwise circumvent security mechanisms. If an attacker can simply turn off MDE/MDAV when trying to compromise a system, life gets a lot easier. As defenders, we want to stop that.
Tamper protection for Microsoft Defender Antivirus is an on-by-default capability to make evasion harder. It is available for Windows 10/Server 2016 or later, and Windows Server 2012 R2 with the unified agent.
Malware or intruders can try to evade MDAV in several ways. The registry editor, PowerShell, Intune, Group Policy (local or Active Directory), and MpCmdRun.exe
: these all allow a legitimate or illegitimate user to tamper with protection. When enabled, tamper protection restricts such methods of editing settings. Let’s reiterate that: when tamper protection is enabled, you cannot disable certain features of MDAV, even...