Skip to content
Threat Feed
high advisory

Abuse of Microsoft Defender Antivirus Exclusions for Malware Evasion

Adversaries leverage legitimate Microsoft Defender Antivirus exclusion settings via PowerShell, WMI, and GPO to bypass real-time scanning and hide malicious payloads from endpoint detection.

Adversaries are increasingly exploiting Microsoft Defender Antivirus (MDAV) exclusions to maintain undetected persistence and execute malicious binaries without triggering security alerts. By manipulating exclusion settings, attackers can bypass real-time monitoring, scheduled scans, and on-demand analysis for specific paths, processes, file extensions, or network traffic.

The technique requires elevated privileges (administrator or higher). Once elevated, attackers interact with the MDAV engine (MsMpEng.exe) through legitimate administrative interfaces, specifically PowerShell's Set-MpPreference or Add-MpPreference cmdlets, the MSFT_MpPreference WMI class, or by pushing Group Policy Objects (GPO) to target systems. These actions update registry keys under HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions or policy-based registry locations. Historical campaigns, including GootKit (2019), WhisperGate (2022), and Muddled Libra (2024), demonstrate that threat actors use these methods to exclude staging directories or entire drives (like C:) from protection, enabling the unhindered execution of malware.

Impact

Successful abuse of MDAV exclusions renders endpoint protection ineffective, allowing attackers to deploy and execute ransomware, infostealers, or persistence mechanisms without interference. This evasion technique increases the dwell time of attackers within a network, as traditional signature-based and heuristic detection capabilities are blinded to the excluded content. This remains a significant risk for organizations where administrative privilege hygiene is poor, allowing attackers to easily modify security preferences to suit their campaign objectives.

Recommendation

  • Implement strict Principle of Least Privilege (PoLP) to limit the number of users and processes with the authority to modify Defender preferences.
  • Monitor PowerShell and WMI activity for calls to Set-MpPreference or Add-MpPreference using suspicious parameters like ExclusionPath.
  • Audit existing Defender exclusions across the fleet to identify unauthorized or broad directory exclusions, such as those targeting the entire C:\ drive.
  • Deploy the Sigma rules below to detect unauthorized modifications to Defender settings via PowerShell and WMI.

Immediate actions

Review current MDAV exclusion policies via Group Policy or CSP to ensure no overly permissive paths exist

IT Operations 48h

Threat Hunt

Audit HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions for unexpected paths

T1562.001 high high confidence hunt now

Data: Registry event logs

Detection coverage 1

Detect Suspicious Microsoft Defender Exclusion Modification

high

Detects the addition of Defender exclusions using PowerShell or WMI methods, often indicative of an attacker attempting to hide malicious artifacts.

sigma tactics: defense_evasion techniques: T1562.001 sources: process_creation, windows

Detection queries are available on the platform. Get full rules →