logo

DefendNot: Turning Windows Defender Against Itself

ID: 8b61ee90-eb61-5233-a963-e34529cdfca3

STIX ID: report--8b61ee90-eb61-5233-a963-e34529cdfca3

Feed Name: Binary Defense Blog

Threat Score
70/100

Date Published: 2025-09-03

Date Updated: 2026-04-27

...
...

This report describes DefendNot, a proof-of-concept EDR-killer that abuses the Windows Security Center by registering a spoofed antivirus entry so Windows disables Microsoft Defender, creating stealthy loss of endpoint visibility; the write-up explains the technical mechanism, contrasts it with brute-force EDR-killing tools, and outlines detection traces and remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.