You Can Run, but You Can’t Hide: Defender Exclusions | Huntress
ID: 8f81634c-e94a-53b0-b21c-bf87f33f0e79
STIX ID: report--8f81634c-e94a-53b0-b21c-bf87f33f0e79
Feed Name: Huntress Blog
Threat Score
Huntress details how attackers leverage Microsoft Defender Antivirus exclusions (path/extension) set via PowerShell, WMI, GPO, or registry to bypass scans and evade detection—citing campaigns like GootKit, WhisperGate, and Muddled Libra—and highlights a HideExclusionsFromLocalAdmins registry setting that can conceal exclusions; Huntress added registry telemetry and detection rules for suspicious exclusions and the hide flag.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
