Executive Summary
Facts Only
* MDAV supports four exclusion types: Process, Path, Extension, and IpAddress.
* PowerShell commands Set-MpPreference and Add-MpPreference can be used to set exclusions.
* WMI interaction via MSFTMpPreference class allows for exclusion manipulation.
* Group Policy Objects (GPO) configure exclusions through the path HKEYLOCALMACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions.
* Direct registry modification is constrained, but modifications can target HKEYLOCALMACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths.
* An exclusion setting exists for hiding exclusions from local administrators via the registry key HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\HideExclusionsFromLocalAdmins.
* Telemetry is collected on registry operations to track how exclusions are set.
* Detections are built for suspicious exclusions and modifications to the HideExclusionsFromLocalAdmins setting.
Full Take
From the original · Huntress Labs
The endpoint team at Huntress is focused on providing telemetry and protections around real adversary threats. One thing we've noticed that's often overlooked is adversaries leveraging Microsoft Defender Antivirus (MDAV) settings to circumvent scans on their malicious binaries.Read the full story at huntress.com
Sentinel — Human
The text functions as a technical security analysis detailing how adversaries use Microsoft Defender Antivirus exclusions and outlines a corresponding detection strategy, exhibiting the detailed focus typical of expert technical reporting.
