DefendNot: Turning Windows Defender Against Itself
ID: 8b61ee90-eb61-5233-a963-e34529cdfca3
STIX ID: report--8b61ee90-eb61-5233-a963-e34529cdfca3
Feed Name: Binary Defense Blog
Threat Score
This report describes DefendNot, a proof-of-concept EDR-killer that abuses the Windows Security Center by registering a spoofed antivirus entry so Windows disables Microsoft Defender, creating stealthy loss of endpoint visibility; the write-up explains the technical mechanism, contrasts it with brute-force EDR-killing tools, and outlines detection traces and remediation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
