Serious Discussion Did Microsoft Defender change the way it responds to file downloads?

Microsoft Defender
87 Replies 5,006 Views
It seems that the issue is related to your computer configuration. I tested the EICAR download in Edge, and the file was correctly blocked by MD just after the download.
Do the downloaded files have the Mark of the Web?
Same in my Edge. No issue with detection.
11111.png
 
MD needs a dedicated quarantine subtab, not to search for among history entries.
What if I have erased history by one of the available scripts on Github, where can I find the quarantined files to restore?
I still don't understand. Defender does have a quarantine: Virus & threat protection -> Protection history.

Also, why would you erase detection history? I'm sorry, but it seems to me like you're making up problems just so you could make some kind of excuse.
 
I still don't understand. Defender does have a quarantine: Virus & threat protection -> Protection history.

Also, why would you erase detection history? I'm sorry, but it seems to me like you're making up problems just so you could make some kind of excuse.
Not a dedicated quarantine section like all the peers (Kaspersky, Bitdefender, Avast); a hybrid history/quarantine (no other AV has this brilliant design).

When history is full with entries, I may need to clear as it is becoming confusing.
 
When history is full with entries, I may need to clear as it is becoming confusing.
Protection History has filters: allowed, blocked, quarantined, etc. . I don't see what the problem is. Some Defender users would like a UI that's easier to navigate, but most could care less --> they probably don't even know there's a built-in AV.

"Users just want to use stuff." A number MT oldtimers have repeated this over and over.
 
Protection History has filters: allowed, blocked, quarantined, etc. . I don't see what the problem is. Some Defender users would like a UI that's easier to navigate, but most could care less --> they probably don't even know there's a built-in AV.

"Users just want to use stuff." A number MT oldtimers have repeated this over and over.
So I'll refuse to get nervous, and keep learning more about MD and the settings and options it does have. The EICAR test files have been the only thing that's been flagged by F-Secure and MD in years :)
 
So I'll refuse to get nervous, and keep learning more about MD about the settings and options it does have. The EICAR test files have been the only thing that's been flagged by F-Secure and MD in years :)
I should add that in actuality Defender's PH filter lets you dial-in exactly the kind of items you want to search.
 
Windows Defender just feels clunky, slow, and incomplete
Clunky? to some extent yes
slow? only one second slower to open compared to Avast and Bitdefender, PC performance is as fast as with Avast and Kaspersky
incomplete? No, web protection can be spared without compromise of security, and detection rate is almost equal to Avast, Bitdefender, and Kaspersky
 
Same in my Edge. No issue with detection.
View attachment 299975

Did you test it on the EICAR sample?

On my computer, the sample is automatically detected by MD even when the download is blocked by Edge. The same behavior is with disabled SmartScreen and Potentially app blocking.

Edit.
I do not think that after downloading by Edge, MD checks all file types against the cloud backend. Can you PM the link to the file from your screenshot. I can test the download on my computer.
 
Last edited:
How to check the settings of Block At First Sight:

Verify the configuration​

The following command displays the current block at first sight settings:

PowerShell:
Get-MpPreference | Select-Object MAPSReporting, SubmitSamplesConsent, DisableBlockAtFirstSeen

To verify block at first sight is turned on, confirm the following values:
  • MAPSReporting: 2 (Advanced)
  • SubmitSamplesConsent: 1 (Send safe samples automatically) or 3 (Send all samples automatically)
  • DisableBlockAtFirstSeen: False
 
My apologies for being delinquent in getting my point across.

When I said:

Well, I have made the choice to go with my updated clean install of windows 11.

I am using nothing, other than MSD, and I might just leave it this way since Ai is perfecting the code, security, and usability at such a fast pace.

This pace of 100's of thousands of fixes by Ai, means no one else's code is an appropriate fit, or aligned any longer with Windows 11 changes that happen this fast, unless Bitdefender and Kaspersky have created or purchased the same Ai, Microsoft is using, and correcting their code at the same pace as Microsoft.

This fast pace to fix and secure, would seemingly, possibly not intentionally, push EVERY security product off the chessboard.

To use, a 3rd party product, now with all these changes and improvements, is, in my mind akin to using Kaspersky V, 2001

Or allow me to try to get the point across this way.

I build a gas-powered car, I ask you to make a premium blend of fuel for my car, but then in the process of improving the car, I decide to go with a jet-propelled engine, so you change the fuel, but the process to formulate fuel takes time.

Then I keep making tweaks on this engine to boost its performance, and my tweaking efforts are happening so fast, you can't keep up, because in order to make the fuel to the exact formula I need is a longer process, than the tweaks themselves.

What happens if we accidently use an old formula in the newly tweaked jet-propelled engine, and it messes the engine up.

Thus, we have MS making lightning-fast tweaks, and the AV vendors don't have the time or ability to change their AV to fit the changes, thus it causes harm to the OS.

This is why I am sticking with MS Defender now. It's to up in the air to do otherwise.
 
So I'll refuse to get nervous, and keep learning more about MD and the settings and options it does have.
Haha, haven't you been gorging on the latest statistics (like a 99% → 95.5% block rate!), as some of us do? I am using MD on my computer (with Andy Ful's hardener, etc.), and I am not getting anxious about a single quarterly result (it has been really good before that). My most dangerous activity appears to be getting curious about what's mentioned in this forum 😳!
 
Did you test it on the EICAR sample?
https://secure.eicar.org/eicar_com.zip
On my computer, the sample is automatically detected by MD even when the download is blocked by Edge. The same behavior is with disabled SmartScreen and Potentially app blocking.
Same behavior for me
11111.png

Can you PM the link to the file from your screenshot. I can test the download on my computer.
I checked the samples on urlhaus. So you can check any of them, really. My sample was a .sh script for Linux.
 
I checked the samples on urlhaus. So you can check any of them, really. My sample was a .sh script for Linux.

I cannot without reconfiguring my protection. However, it is very probable that the malware you tested was not detected by BAFS due to unsupported file type. Such files as Windows scripts (.ps, .vbs, .js) or .exe files are supported.
 
I cannot without reconfiguring my protection. However, it is very probable that the malware you tested was not detected by BAFS due to unsupported file type. Such files as Windows scripts (.ps, .vbs, .js) or .exe files are supported.
Same behaviour on an exe malware :unsure:
1789401504207.png

How to check the settings of Block At First Sight:
1789401789281.png
 
Last edited:

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top