Detecting Malicious Security Product Bypass Techniques
ID: 38746e9a-795c-5253-bf72-5d5b493e1472
STIX ID: report--38746e9a-795c-5253-bf72-5d5b493e1472
Feed Name: Huntress Blog
Threat Score
This report analyzes the 'defendnot' tool which injects into trusted processes to interact with the Windows Security Center (WSC) API, register itself as a malicious security product, optionally persist via autorun or scheduled tasks, and ultimately disable Windows Defender; it provides Sigma rules, Sysmon/Windows Event detections, and a robustness-based detection strategy emphasizing behavior/TTP-focused telemetry over ephemeral IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
