One of the possibilities is that the rule "Block use of copied or impersonated system tools" can block files after opening the folder (no need to execute anything). For example:
*******************************************************
Event[0]:
Time Created : 26/06/2025 00:02:18
ProviderName : Microsoft-Windows-Windows Defender
Id : 1121
Message : Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator.
For more information please contact your IT administrator.
ID: c0033c00-d16d-4114-a5a0-dc9b3a7d2ceb
ConfigureDefender option: Block use of copied or impersonated system tools
Detection time: 2025-06-25T22:02:18.183Z
User:
Path: C:\Test\sdclt.exe
Process Name: C:\Windows\explorer.exe
Target Commandline:
Parent Commandline: "C:\Windows\explorer.exe" /LOADSAVEDWINDOWS
Involved File:
Inheritance Flags: 0x00000000
Security intelligence Version: 1.431.208.0
Engine Version: 1.1.25050.6
Product Version: 4.18.25050.5
*******************************************************
This means that the block event could be triggered by accident when installing the driver (but unrelated to the driver).
*******************************************************
Event[0]:
Time Created : 26/06/2025 00:02:18
ProviderName : Microsoft-Windows-Windows Defender
Id : 1121
Message : Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator.
For more information please contact your IT administrator.
ID: c0033c00-d16d-4114-a5a0-dc9b3a7d2ceb
ConfigureDefender option: Block use of copied or impersonated system tools
Detection time: 2025-06-25T22:02:18.183Z
User:
Path: C:\Test\sdclt.exe
Process Name: C:\Windows\explorer.exe
Target Commandline:
Parent Commandline: "C:\Windows\explorer.exe" /LOADSAVEDWINDOWS
Involved File:
Inheritance Flags: 0x00000000
Security intelligence Version: 1.431.208.0
Engine Version: 1.1.25050.6
Product Version: 4.18.25050.5
*******************************************************
This means that the block event could be triggered by accident when installing the driver (but unrelated to the driver).
