New Update DefenderUI by VoodooShield - Turn on Hidden Security Features of Microsoft Defender

danb

From VoodooShield
Thread author
Verified
Top Poster
Developer
Well-known
May 31, 2017
1,719
When yesterday I tried selecting Interactive it forced Custom Mode with Tamper Protection enabled.
Today I changed profile to Aggressive and ignored TP prompt, it did not revert to Custom.
DUI is on Aggressive mode with MD Tamper protection On. Will there be conflict?
Please tell me if I am barking up the wrong tree with what I'm doing and just disable Tamper Protection. Do not whish to take up your valuable time
Sorry, I forgot to mention that the Custom Profile in the drop down is not active yet. Once it is active, it will auto save the Custom Profile, and we may even have an option to save the profile. A lot of this depends on exactly how many options we have.
 

show-Zi

Level 36
Verified
Top Poster
Well-known
Jan 28, 2018
2,464
I removed ConfiguredDefender to install DUI. Nothing wrong with CD, at the contrary I am pleased, just wanting to experiment with DUI on its own.
@show-Zi you seems to be running both, with not conflict apparent. How are you able to asses which of the two is actually doing the work and how they complement each other?
I guess it easy for anybody who has more than a basic knowledge of these things. But doesn't hurt asking.
I envision applying a C-Defender and then tweaking it in the Defender UI.:)
I would like to leave the testing and evaluation of Defender UI to other knowledgeable members.
...At any rate, I lack the knowledge.;)
 

Tutman

Level 12
Verified
Top Poster
Well-known
Apr 17, 2020
542
I totally agree, I am just saying "so far, so good" ;).

Thank you, same to you! Once I am finished, there should be several features that make Microsoft Defender more robust and foolproof.

Yes, I have not figured out how to handle that yet, but I have some ideas. It might just be best to ask the user uninstall DefenderUI if another AV is registered as the primary AV. Or if there are enough features once I am finished, maybe we can have a different mode and it will only show the relevant features. It is hard to say at this point ;).
I was just going to ask if we could use this with a third party AV. Keep up the good work!
 

danb

From VoodooShield
Thread author
Verified
Top Poster
Developer
Well-known
May 31, 2017
1,719
I was just going to ask if we could use this with a third party AV. Keep up the good work!
Really it all depends on if DefenderUI offers features you want or not, and also depends on if your third party AV completely disables MD, or allows it to run background scans. In a few years it is not going to matter... everyone is going to be running MD ;).
 

danb

From VoodooShield
Thread author
Verified
Top Poster
Developer
Well-known
May 31, 2017
1,719
Hey guys,

Here is the latest... there is still quite a bit to do, but we should have a fully functional product in 2-3 weeks. It really turned out to be a lot more work than I initially envisioned, but isn't that always the case? It kinda does not matter because we are probably going to be adding features to DefenderUI for years to come.... I just want to get to the point where we have a fully functional, stable product.

So there are a lot of things are are unfinished, for example, the scans are almost complete, but if you select more than one directory for a Custom Scan, DefenderUI will mess up.


Thank you guys!

Dan
 

danb

From VoodooShield
Thread author
Verified
Top Poster
Developer
Well-known
May 31, 2017
1,719
I almost forgot... from what I have seen, the "Average CPU utilization while scanning" MS setting does not seem to work as expected. Which is probably why a lot of people complain that MD uses ungodly amounts of CPU cycles. We should be able to fix this for good, and the "Average CPU utilization while scanning" will be named something else, and it should actually work ;).

The reason I mention this... I have never ran a full MD scan on my computer until I ran a Full Scan from DefenderUI. It COMPLETELY MAXED OUT all of my cores, for like a long time. I then tested with running a normal MD Full Scan (once I was able to find it ;)), I had the same result... maxed cores, for a very long time.

Anyway, we should be able to fix this as well.
 

danb

From VoodooShield
Thread author
Verified
Top Poster
Developer
Well-known
May 31, 2017
1,719
Hey guys,

Here is the latest. There were a lot of changes under the hood, and I think we are almost completely stable and ready to start adding the other features, which should go pretty quick since everything is now in place. Each new feature should only take around 30-60 minutes to implement and test, so all of the hard work should be in our rearview mirror.

As I was saying, I think it is important to make CD and DefenderUI as compatible as possible so that users can switch between the two without too much confusion. The 2 are syncing quite nicely now, except for the “Signature Update Interval” feature. Basically, if you are testing them to see if they sync, please make sure the “Signature Update Interval” is set to Default for the Default Profile, and 2 Hours for the other profiles. Having said that, now that we are going to be adding new features, we will probably encounter the same issue with the new features as we add them. Maybe Andy can include the new features in CD so that they match perfectly. Then everyone will have the best of both worlds… if they want a portable app with no realtime features, they can use CD. If they want an app with realtime features, they can use DefenderUI. Also, if Andy ever wants to create a realtime version of CD, I will happily discontinue development of DefenderUI. I am not trying to step on anyone’s toes, but I really did want a realtime Defender UI, and I figured if I was going to go through all of the work, I might as well release it to MT members, for those who want such an animal ;). It really did turn into A LOT more work than I initially envisioned, but we are in a VERY good place now. There might be a few small bugs to fix, but besides that, we just need to add features at this point, which is more busy work than anything else.

One of the biggest changes to this version is that DefenderUI now only spawns one powershell instance when performing several tasks, like changing profiles. It also only includes the commands that are necessary for each function.

Also, the scans should be pretty much finished now. We might be able to display the scan results in DefenderUI, which was the original plan. But I kinda like it the way it is, simply because if a threat is found, it is best for MD to take over and do its thing.

As far as new features go, I have not decided which ones to add, but I am compiling a list and I will probably post the list to see which features you guys think we should add. And actually, we can add a few non-MD features, like maybe a link to the Control Panel. So if anyone has any suggestions for these types of features, please let me know!

DefenderUI should auto update itself the next time you start it, but if it does not, here is a link

DefenderUI 0.59 beta
SHA-256: 8fd99028d44ecd5d9b919fb395557d15e7037fb287c9b96e04cbab5705a19a4f

Thank you guys!
 

show-Zi

Level 36
Verified
Top Poster
Well-known
Jan 28, 2018
2,464
We are happy to see that development is progressing well.
I'd like to make some adjustments, but I'm hesitant because I'm worried that a misinterpretation of the English text will lead to unintended consequences.
As such, I'm eagerly awaiting the ability to save and load custom profiles.:)
 

danb

From VoodooShield
Thread author
Verified
Top Poster
Developer
Well-known
May 31, 2017
1,719
We are happy to see that development is progressing well.
I'd like to make some adjustments, but I'm hesitant because I'm worried that a misinterpretation of the English text will lead to unintended consequences.
As such, I'm eagerly awaiting the ability to save and load custom profiles.:)
Absolutely ;). Once all of the new features are somewhat in place this is the first thing I will do ;). Thank you!
 

danb

From VoodooShield
Thread author
Verified
Top Poster
Developer
Well-known
May 31, 2017
1,719
Ok, this is interesting. I had not tried W11 since it was leaked, so maybe 2-3 months ago, and the Windows Settings screen looked like this...



And now it looks like this...

Taskbarnew.PNG


Maybe there is a chance they are going to update the MD UI ;). If so, I will take a nap.

I do not pat myself on the back that often, but I have to admit that my guess on what W11 would end up looking like was somewhat close (especially considering that I suck with graphic design) ;). The whole point of DefenderUI is for it to blend in seamlessly with W11, so at this point I am making a lot of guesses, but I was absolutely shocked to see the latest W11 settings screen.

Anyway, if MS creates an amazing UI for Defender, that would be truly amazing. They do amazing work. Who knows, maybe they will even start to lock the computer when it is at risk ;). Then, and only then will they be offering TRUE Defense-in-depth.


In other words, you can never have Defense-in-depth without dynamic security postures ;).
 

pxxb1

Level 10
Verified
Well-known
Jan 17, 2018
473
Ok, this is interesting. I had not tried W11 since it was leaked, so maybe 2-3 months ago, and the Windows Settings screen looked like this...



And now it looks like this...

View attachment 260349

Maybe there is a chance they are going to update the MD UI ;). If so, I will take a nap.

I do not pat myself on the back that often, but I have to admit that my guess on what W11 would end up looking like was somewhat close (especially considering that I suck with graphic design) ;). The whole point of DefenderUI is for it to blend in seamlessly with W11, so at this point I am making a lot of guesses, but I was absolutely shocked to see the latest W11 settings screen.

Anyway, if MS creates an amazing UI for Defender, that would be truly amazing. They do amazing work. Who knows, maybe they will even start to lock the computer when it is at risk ;). Then, and only then will they be offering TRUE Defense-in-depth.


In other words, you can never have Defense-in-depth without dynamic security postures ;).


This is going to be a hit, mark my words!

Will it come in light mode also, so even i can be chocked?
Still the frame opens at the bottom when i click at the DUI icon at the top on W11.
 

Gandalf_The_Grey

Level 83
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
7,259
Hey guys,

Here is the latest. There were a lot of changes under the hood, and I think we are almost completely stable and ready to start adding the other features, which should go pretty quick since everything is now in place. Each new feature should only take around 30-60 minutes to implement and test, so all of the hard work should be in our rearview mirror.

As I was saying, I think it is important to make CD and DefenderUI as compatible as possible so that users can switch between the two without too much confusion. The 2 are syncing quite nicely now, except for the “Signature Update Interval” feature. Basically, if you are testing them to see if they sync, please make sure the “Signature Update Interval” is set to Default for the Default Profile, and 2 Hours for the other profiles. Having said that, now that we are going to be adding new features, we will probably encounter the same issue with the new features as we add them. Maybe Andy can include the new features in CD so that they match perfectly. Then everyone will have the best of both worlds… if they want a portable app with no realtime features, they can use CD. If they want an app with realtime features, they can use DefenderUI. Also, if Andy ever wants to create a realtime version of CD, I will happily discontinue development of DefenderUI. I am not trying to step on anyone’s toes, but I really did want a realtime Defender UI, and I figured if I was going to go through all of the work, I might as well release it to MT members, for those who want such an animal ;). It really did turn into A LOT more work than I initially envisioned, but we are in a VERY good place now. There might be a few small bugs to fix, but besides that, we just need to add features at this point, which is more busy work than anything else.

One of the biggest changes to this version is that DefenderUI now only spawns one powershell instance when performing several tasks, like changing profiles. It also only includes the commands that are necessary for each function.

Also, the scans should be pretty much finished now. We might be able to display the scan results in DefenderUI, which was the original plan. But I kinda like it the way it is, simply because if a threat is found, it is best for MD to take over and do its thing.

As far as new features go, I have not decided which ones to add, but I am compiling a list and I will probably post the list to see which features you guys think we should add. And actually, we can add a few non-MD features, like maybe a link to the Control Panel. So if anyone has any suggestions for these types of features, please let me know!

DefenderUI should auto update itself the next time you start it, but if it does not, here is a link

DefenderUI 0.59 beta
SHA-256: 8fd99028d44ecd5d9b919fb395557d15e7037fb287c9b96e04cbab5705a19a4f

Thank you guys!
DefenderUI 0.59 beta seems to work great initially, but after a reboot it doesn't work anymore on my system:

Schermafbeelding 2021-08-31 174102.pngSchermafbeelding 2021-08-31 174132.pngSchermafbeelding 2021-08-31 174150.png
Any ideas what's causing this?
 

danb

From VoodooShield
Thread author
Verified
Top Poster
Developer
Well-known
May 31, 2017
1,719
This is going to be a hit, mark my words!

Will it come in light mode also, so even i can be chocked?
Still the frame opens at the bottom when i click at the DUI icon at the top on W11.
Thank you, I appreciate that! The Dark / Light mode feature is not quite ready, but it will be soon. I also need to fix the desktop icon ;).
 

danb

From VoodooShield
Thread author
Verified
Top Poster
Developer
Well-known
May 31, 2017
1,719
DefenderUI 0.59 beta seems to work great initially, but after a reboot it doesn't work anymore on my system:

View attachment 260353View attachment 260354View attachment 260355
Any ideas what's causing this?
Hmm, it's hard to say because I cannot see exactly what the issue is. This is odd because I am running DefnderUI on 5 computers total... last night I tested on 2 W11 machines, all without issue. So there must be a simple explanation.

You can maybe try a couple of things...

1) Uninstall, reboot and reinstall
2) After reinstalling, select the Default profile first, then select whatever profile you want to use.
3) You can also check Windows event viewer for any errors / exceptions. Instead of having a dedicated developer log for DefenderUI, I chose to just write any errors to the Windows event viewer.
 

danb

From VoodooShield
Thread author
Verified
Top Poster
Developer
Well-known
May 31, 2017
1,719
I do not think that I could make a better GUI.:)(y)
Thank you, I appreciate that! From the looks of it, it Redmond decides to update the MD section of Windows Settings, we may not need a realtime Defender GUI ;). But I am close enough that I am going to finish it anyway, just in case. Besides, I highly doubt they make it easy to temporarily disable the realtime and cloud based protections.

Depending on what happens with VS in the next couple of months, I might even make DefenderUI open source, post it on GitHub, and head to the lake ;).
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top