Security News Hackers Abuse Microsoft Defender Exclusions to Hide Malware From Antivirus Scans

Security News
7 Replies 280 Views

Parkinsond

Level 67
Verified
Top Poster
Well-known
Huntress also examined a policy setting that hides exclusions from local administrators querying them through PowerShell.

Despite its name, the same setting prevented queries made under SYSTEM, a privileged Windows account. That can create a misleading impression that no exclusions exist when the configuration has simply been concealed.

Registry monitoring provides a broader view because exclusion changes ultimately reach the registry regardless of the administration method used.

 
I used Duck's ChatGPT to make suggestions for consumers:

You’re right—the full forensic approach is too complicated for most people. Consumers should use a risk-based shortcut, not try to audit every possible Defender configuration manually.

A practical approach is:

1. Check the normal Defender exclusions list​

Open Windows Security → Virus & threat protection → Manage settings → Exclusions. Remove anything you don’t recognize.

2. Run one elevated PowerShell command​


Code:
Get-MpPreference | Select-Object ExclusionPath,ExclusionExtension,ExclusionProcess,ExclusionIpAddress

If all four fields are empty, that is a reasonable consumer-level check—not an absolute forensic guarantee.

3. Check whether exclusions are being hidden​


Code:
Get-MpPreference | Select-Object DisableLocalAdminMerge

If you’re concerned about the article’s concealment scenario, check:

Code:
Get-ItemProperty `
  'HKLM:\SOFTWARE\Policies\Microsoft\Windows Defender' `
  -Name HideExclusionsFromLocalAdmins `
  -ErrorAction SilentlyContinue

If that returns `1`, or if the computer is managed by a workplace or school, don’t assume an empty exclusion list means the system is clean.

4. Use Microsoft Defender Offline scan if anything looks suspicious​


Go to Windows Security → Virus & threat protection → Scan options → Microsoft Defender Offline scan. This restarts the PC and scans before normal Windows processes load, making it harder for active malware to interfere.

5. Use a second-opinion scanner​

Run an on-demand scan with a reputable, up-to-date security product. A second scanner is generally more useful to a typical consumer than manually investigating every possible registry and policy path.

The important distinction is:
  • Ordinary home user: Windows Security check + PowerShell check + Offline scan if concerned.
  • Work/school computer: Ask the administrator; policies may intentionally configure exclusions.
  • Evidence of compromise: Disconnect from the internet and use professional incident-response help (😏) rather than trying to prove the machine is clean manually.
So yes: consumers cannot realistically guarantee that every Defender exclusion mechanism is absent. The sensible goal is to detect obvious or dangerous exclusions and use layered scanning—not to perform a complete Windows security audit.
 
I used to check the exclusions once daily, but according to the article, there might be some without being dispalyed in Windows security.

If the policy HideExclusionsFromLocalAdmins is set in the system, you can see this when checking exclusions via Security Center (the text in red):

1790935125371.png
 
Last edited:
Yes I have tried before; exclusion section get disabled in Windows security.

But is it a guarantee no exclusions can be added by malware through registry?

You do not get the information that "exclusion section get disabled" but that "You do not have the proper permissions to view ...". This is specific info related to the HideExclusionsFromLocalAdmins policy.
When this policy is set, Malware can add exclusions and you cannot see them via PowerShell or Security Center.
I created ConfigureDefenderPM to prevent attacks reported in the article.
 
Last edited:
You do not get the information that "exclusion section get disabled" but that "You do not have the proper permissions to view ...". This is specific info related to the HideExclusionsFromLocalAdmins policy.
When this policy is set, Malware can add exclusions and you cannot see them via PowerShell or Security Center.
I created ConfigureDefenderPM to prevent attacks reported in the article.
How reassuring to know; thank you, Andy.
 

Recently browsing

Members who viewed this thread in the last 5 minutes

You may also like...

Continue exploring the conversation.

Back
Top