Reply to thread

It is possible to test WHHLight default settings with Microsoft Defender on default settings with disabled real-time protection + FirewallHardening + DocumentsAntiExploit (MS Office and Acrobat Reader open documents by default).

Other Defender's settings (like Cloud Delivered Protection) must be enabled.

WHHLight in default settings requires additional protection against weaponized documents (such as DocumentsAntiExploit). Default settings highly restrict scripting attacks, but allow CmdLines with LOLBins (useful for system management). So, FirewallHardening is also required to restrict LOLBins.


About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top