(TargetObject:\\Control\\WMI\\Autologger\\* ((TargetObject:\\EventLog\-* OR TargetObject:\\Defender*) (TargetObject:\\Enabled OR TargetObject:\\Start) Details:DWORD\ \(0x00000000\))) (-(Image:C\:\\Windows\\system32\\wevtutil.exe OR ((Image:C\:\\ProgramData\\Microsoft\\Windows\ Defender\\Platform\\* OR Image:C\:\\Program\ Files\\Windows\ Defender\\* OR Image:C\:\\Program\ Files\ \(x86\)\\Windows\ Defender\\*) Image:\\MsMpEng.exe (TargetObject:\\DefenderApiLogger\\* OR TargetObject:\\DefenderAuditLogger\\*))))