Security News Hackers Abuse Microsoft Defender Exclusions to Hide Malware From Antivirus Scans

Security News
3 Replies 119 Views

Parkinsond

Level 67
Verified
Top Poster
Well-known
Huntress also examined a policy setting that hides exclusions from local administrators querying them through PowerShell.

Despite its name, the same setting prevented queries made under SYSTEM, a privileged Windows account. That can create a misleading impression that no exclusions exist when the configuration has simply been concealed.

Registry monitoring provides a broader view because exclusion changes ultimately reach the registry regardless of the administration method used.

 
I used Duck's ChatGPT to make suggestions for consumers:

You’re right—the full forensic approach is too complicated for most people. Consumers should use a risk-based shortcut, not try to audit every possible Defender configuration manually.

A practical approach is:

1. Check the normal Defender exclusions list​

Open Windows Security → Virus & threat protection → Manage settings → Exclusions. Remove anything you don’t recognize.

2. Run one elevated PowerShell command​


Code:
Get-MpPreference | Select-Object ExclusionPath,ExclusionExtension,ExclusionProcess,ExclusionIpAddress

If all four fields are empty, that is a reasonable consumer-level check—not an absolute forensic guarantee.

3. Check whether exclusions are being hidden​


Code:
Get-MpPreference | Select-Object DisableLocalAdminMerge

If you’re concerned about the article’s concealment scenario, check:

Code:
Get-ItemProperty `
  'HKLM:\SOFTWARE\Policies\Microsoft\Windows Defender' `
  -Name HideExclusionsFromLocalAdmins `
  -ErrorAction SilentlyContinue

If that returns `1`, or if the computer is managed by a workplace or school, don’t assume an empty exclusion list means the system is clean.

4. Use Microsoft Defender Offline scan if anything looks suspicious​


Go to Windows Security → Virus & threat protection → Scan options → Microsoft Defender Offline scan. This restarts the PC and scans before normal Windows processes load, making it harder for active malware to interfere.

5. Use a second-opinion scanner​

Run an on-demand scan with a reputable, up-to-date security product. A second scanner is generally more useful to a typical consumer than manually investigating every possible registry and policy path.

The important distinction is:
  • Ordinary home user: Windows Security check + PowerShell check + Offline scan if concerned.
  • Work/school computer: Ask the administrator; policies may intentionally configure exclusions.
  • Evidence of compromise: Disconnect from the internet and use professional incident-response help (😏) rather than trying to prove the machine is clean manually.
So yes: consumers cannot realistically guarantee that every Defender exclusion mechanism is absent. The sensible goal is to detect obvious or dangerous exclusions and use layered scanning—not to perform a complete Windows security audit.
 

Recently browsing

Members who viewed this thread in the last 5 minutes

You may also like...

Continue exploring the conversation.

Back
Top