Skip to content
Threat Feed

Tag

Windows-Defender

20 briefs RSS
critical advisory

Windows Defender Race Condition (EDB-52612) Leads to Local Privilege Escalation and AV Bypass

A critical local race condition (EDB-52612) exists in Microsoft Windows Defender's MsMpEng.exe, specifically between its cleanup routine (`MpCleanCallbackFunction`) and Volume Shadow Copy creation, allowing Local Privilege Escalation (LPE) to NT AUTHORITY\SYSTEM and temporary disabling of antivirus protection through a use-after-free vulnerability, with a public exploit demonstrating the risk.

Windows Defender Antivirus local-privilege-escalation race-condition windows-defender exploit-db vulnerability endpoint
1t 3i
high advisory

Windows Defender Tampering via WMIC for Defense Evasion

A technique brief describes how adversaries may use `wmic.exe` to tamper with Windows Defender settings, specifically to add exclusions via the `\root\Microsoft\Windows\Defender` WMI namespace, reducing the host's security posture and enabling further malicious activity.

defense-evasion wmic windows-defender endpoint-security windows
1r 2t
high advisory

Windows Defender Controlled Folder Access Disabled via Registry Modification

An attacker modifies the Windows registry to disable Windows Defender Controlled Folder Access, a defense evasion technique that weakens protections against unauthorized access and ransomware.

Splunk Enterprise +3 defense-evasion registry-modification windows-defender
2r 1t
high advisory

Suspicious PowerShell Command Removing Windows Defender Directory

A PowerShell command attempting to remove the Windows Defender directory is detected via PowerShell Script Block Logging, potentially indicating an attacker's attempt to disable endpoint protection for further malicious activities.

Windows Defender +3 powershell defense-evasion windows-defender endpoint
2r 1t
high advisory

Windows Defender Submit Samples Consent Feature Disabled via Registry Modification

Attackers modify the Windows Registry to disable the Windows Defender Submit Samples Consent feature, preventing sample submission for analysis and enabling potential system compromise.

Windows Defender defense-evasion registry-modification windows-defender
2r 1t
medium advisory

Windows Defender Signature Retirement Disabled via Registry Modification

An attacker disables Windows Defender's signature retirement feature by modifying a registry key, potentially reducing its effectiveness in detecting threats by allowing older, less relevant signatures to persist.

Windows Defender +3 defense-evasion windows-registry windows-defender
2r 1t
medium advisory

Windows Defender Scan On Update Disabled via Registry Modification

An attacker modifies the Windows registry to disable the Windows Defender Scan On Update feature, potentially evading detection and establishing persistence.

Windows Defender +3 defense-evasion registry-modification windows-defender
2r 1t
high advisory

Windows Defender Real-time Signature Delivery Disabled via Registry Modification

The following analytic detects modifications to the Windows registry that disable the Windows Defender real-time signature delivery feature, preventing timely malware definition updates and potentially leading to system compromise.

Splunk Enterprise +3 defense-evasion windows-defender registry-modification endpoint
2r 1t
high advisory

Windows Defender Network Protection Disabled via Registry Modification

Attackers disable Windows Defender Network Protection by modifying the `EnableNetworkProtection` registry value, potentially bypassing network-based threat detection and enabling data exfiltration or further system compromise.

Windows Defender defense-evasion registry-modification windows-defender
2r 1t
high threat

Windows Defender MpEngine Disabled via Registry Modification

An attacker modifies the Windows Defender MpEngine registry value to disable key features, potentially allowing malware to evade detection.

Windows Defender IcedID defense-evasion registry-modification windows-defender
2r 1t
high advisory

Windows Defender File Hash Computation Disabled via Registry Modification

Attackers may disable Windows Defender's ability to compute file hashes by modifying the EnableFileHashComputation registry value, impairing its malware detection capabilities.

Windows Defender +3 defense-evasion registry-modification windows-defender
2r 1t
high advisory

Windows Defender Evasion via Protected Process Light (PPL) Manipulation

An attacker can potentially evade Windows Defender by manipulating Protected Process Light (PPL) attributes, allowing malicious processes to operate with elevated privileges and avoid security scans.

Windows +1 ppl windows-defender evasion
2r 2t
high advisory

Windows Defender Enhanced Notification Disabled via Registry Modification

An attacker modifies the Windows Registry to disable Windows Defender's Enhanced Notification feature, preventing users from receiving security alerts and potentially allowing malicious activities to go unnoticed, ultimately enabling persistence and evasion.

Windows Defender +3 registry-modification windows-defender persistence evasion
2r 1t
high advisory

Windows Defender Controlled Folder Access Disabled via Registry Modification

This analytic detects a Windows registry modification that disables the Windows Defender Controlled Folder Access feature, potentially allowing attackers to bypass a key security control and gain unauthorized access to sensitive files.

Windows Defender defense-evasion registry-modification windows-defender
2r 1t
high advisory

Windows Defender ASR or Threat Configuration Tampering

Adversaries tamper with Windows Defender's Attack Surface Reduction (ASR) rules or threat default actions using Add-MpPreference or Set-MpPreference commands, aiming to bypass the security tool for undetected malicious code execution.

Windows Defender +3 defense-evasion windows-defender endpoint
2r 1t
high advisory

PowerShell Used to Disable Windows Defender Security Monitoring

Attackers are using PowerShell commands with specific Set-MpPreference parameters to disable Windows Defender's real-time behavior monitoring, a common tactic for malware to evade detection and persist on compromised systems.

Windows Defender powershell windows-defender defense-evasion endpoint
3r 1t
high advisory

Detecting Disabling of Windows Defender Sample Submission

An attacker modifies the Windows registry to disable the Windows Defender Submit Samples Consent feature, preventing the submission of suspicious files for analysis, and potentially evading detection.

Splunk Enterprise +3 defense-evasion registry-modification windows-defender
2r
medium advisory

Windows Defender Quick Scan Interval Modification

Detection of modifications to the Windows registry that change the Windows Defender Quick Scan Interval, potentially impairing its ability to detect malware promptly.

Splunk Enterprise +3 defense-evasion windows-registry windows-defender endpoint
2r 1t
high advisory

PowerShell Windows Defender Exclusion Commands

Attackers use PowerShell commands with `Add-MpPreference` or `Set-MpPreference` to create Windows Defender exclusions, allowing malware to execute undetected.

Windows Defender powershell windows-defender exclusion defense-evasion
2r 1t
high advisory

PowerShell Used to Disable Windows Defender Security Monitoring

This analytic identifies attempts to disable Windows Defender real-time behavior monitoring via PowerShell commands using `Set-MpPreference`, commonly used by malware to evade detection and potentially leading to data exfiltration or system compromise.

Windows Defender defense-evasion powershell windows-defender
2r 1t