You have 1,000 on-premises Windows 11 Pro devices that are onboarded to Microsoft Defender for Endpoint.
You have a Microsoft 365 subscription that uses Microsoft Defender XDR.
You identify that an attacker performed the following actions on a device:
• Modified the filesystem path of a registry-based antivirus exclusion
• Downloaded a malicious file to the file system path
You initiate a live response session on the device.
You need to undo the registry change.
Which command should you run?
xRiot007
Highly Voted 3 months, 2 weeks ago