Product
Windows Defender
- First Reported
- Feb 23, 2026
- Latest Reported
- Sep 1, 2026
Reported Context (2)
- In addition, multiple intrusions involved PowerShell to enforce monitoring exclusions for Windows Defender. For example, the following command excluded an entire directory (the C: drive) from scanning, effectively Sophos Details GOLD SHERWOOD’s The Gentlemen Ransomware Playbook
- This LOLBIN was used to disable Windows Defender settings on the server. Apache ActiveMQ Exploit Led to LockBit Ransomware Deployment
CVE (2)
Malware (2)
People (3)
Threat Actors (1)
MITRE ATT&CK (30)
Vendors (1)
Products (10)
Tools (20)
Countries (1)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.