logo

Windows Defender bypass

ID: 4e7a83e0-2ed9-50c9-b7bb-26ca7ec77a0f

STIX ID: report--4e7a83e0-2ed9-50c9-b7bb-26ca7ec77a0f

Feed Name: ThreatLocker Blog

Threat Score
75/100

Date Published: 2025-01-03

Date Updated: 2026-05-01

...
...

This report demonstrates a proof-of-concept bypass of Windows Defender (CVE-2023-24934) in which an attacker hijacks the Defender update process to delete Mimikatz from the signature database, allowing its download and execution; affected Defender versions are prior to 4.18.2303.8, the exploit and PoC tool (wd-pretender.py) are publicly documented, and mitigations include patching Defender and using application allowlisting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.