logo

Detecting Malicious Security Product Bypass Techniques

ID: 38746e9a-795c-5253-bf72-5d5b493e1472

STIX ID: report--38746e9a-795c-5253-bf72-5d5b493e1472

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2025-05-23

Date Updated: 2026-04-28

...
...

This report analyzes the 'defendnot' tool which injects into trusted processes to interact with the Windows Security Center (WSC) API, register itself as a malicious security product, optionally persist via autorun or scheduled tasks, and ultimately disable Windows Defender; it provides Sigma rules, Sysmon/Windows Event detections, and a robustness-based detection strategy emphasizing behavior/TTP-focused telemetry over ephemeral IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.