Windows Defender ACL Blocking: A Silent Technique With Serious Impact
ID: 4136589b-4542-593d-9c9c-d5c6ff47ba87
STIX ID: report--4136589b-4542-593d-9c9c-d5c6ff47ba87
Feed Name: Binary Defense Blog
Threat Score
**Executive summary:** This report analyzes a proof-of-concept tool that, with admin privileges, modifies kernel32.dll ACLs to add Deny entries for service SIDs (targeting Windows Defender and Sysmon by default), causing affected services to fail to start after reboot; it documents detection methods (Security Event IDs 4670/4663 and KQL queries) and provides practical defensive guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
