logo

You Can Run, but You Can’t Hide: Defender Exclusions | Huntress

ID: 8f81634c-e94a-53b0-b21c-bf87f33f0e79

STIX ID: report--8f81634c-e94a-53b0-b21c-bf87f33f0e79

Feed Name: Huntress Blog

Threat Score
65/100

Date Published: 2024-11-21

Date Updated: 2026-04-28

...
...

Huntress details how attackers leverage Microsoft Defender Antivirus exclusions (path/extension) set via PowerShell, WMI, GPO, or registry to bypass scans and evade detection—citing campaigns like GootKit, WhisperGate, and Muddled Libra—and highlights a HideExclusionsFromLocalAdmins registry setting that can conceal exclusions; Huntress added registry telemetry and detection rules for suspicious exclusions and the hide flag.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.