Skip to content

Executive Summary

Adversaries can circumvent Microsoft Defender Antivirus (MDAV) scans by leveraging specific exclusion settings. MDAV supports four types of exclusions: Process, Path, Extension, and IpAddress. Attackers utilize these exclusions stealthily to avoid detection by removing files or paths from real-time, scheduled, on-demand, and real-time protection. The methods for setting exclusions vary, including PowerShell cmdlets (Set-MpPreference/Add-MpPreference), WMI, Group Policy Objects (GPO), and direct registry modification. Execution flows differ based on the method; for instance, PowerShell calls often route through WMI to MsMpEng.exe which modifies a specific registry key. Attackers most commonly exploit Path and Extension exclusions. Furthermore, adversaries can attempt to hide these settings from administrators by modifying the HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\HideExclusionsFromLocalAdmins registry value, although system users may retain query access via direct registry access.

Facts Only

* MDAV supports four exclusion types: Process, Path, Extension, and IpAddress.
* PowerShell commands Set-MpPreference and Add-MpPreference can be used to set exclusions.
* WMI interaction via MSFTMpPreference class allows for exclusion manipulation.
* Group Policy Objects (GPO) configure exclusions through the path HKEYLOCALMACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions.
* Direct registry modification is constrained, but modifications can target HKEYLOCALMACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths.
* An exclusion setting exists for hiding exclusions from local administrators via the registry key HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\HideExclusionsFromLocalAdmins.
* Telemetry is collected on registry operations to track how exclusions are set.
* Detections are built for suspicious exclusions and modifications to the HideExclusionsFromLocalAdmins setting.

Full Take

The existence of multiple, distinct pathways—PowerShell, WMI, GPO, and direct registry access—to configure security settings like MDAV exclusions reveals a systemic challenge in centralized control and visibility within endpoint security environments. The layered approach where modifications can occur via different execution contexts (user-level vs. system-level) indicates that perimeter defenses must account for configuration persistence across disparate mechanisms. The observation that attackers can specifically conceal their actions by manipulating administrative visibility, even while leaving the underlying data queryable by other system accounts, points to a subtle gap in how security controls manage metadata versus enforcement state. This shifts the focus from simply blocking file access to monitoring the integrity and provenance of configuration changes within the operating system's policy structures. The development of telemetry tracking registry operations and specific flag settings suggests a necessary evolution where visibility extends beyond process-level activity into the manipulation of the underlying system policy layer to achieve true cognitive sovereignty over endpoint state. What are the assumptions built into current telemetry systems regarding administrative intent versus actual system modification, and how can these distinctions be leveraged to build more resilient detection models that focus on anomalous configuration drift rather than just file execution?

From the original · Huntress Labs

The endpoint team at Huntress is focused on providing telemetry and protections around real adversary threats. One thing we've noticed that's often overlooked is adversaries leveraging Microsoft Defender Antivirus (MDAV) settings to circumvent scans on their malicious binaries.
Read the full story at huntress.com

Sentinel — Human

Confidence

The text functions as a technical security analysis detailing how adversaries use Microsoft Defender Antivirus exclusions and outlines a corresponding detection strategy, exhibiting the detailed focus typical of expert technical reporting.

Signals Detected
low severity: Sentence length variance is high; structure shifts from descriptive exposition to highly technical enumeration.
low severity: High coherence, maintaining a clear progression from problem (exclusions) to mechanism (registry paths) to solution (Huntress telemetry). Lacks the overly smooth, passionless balancing of pure AI.
medium severity: Detailed mapping of technical flow and specific examples (PowerShell commands, registry paths) suggests deep domain knowledge or direct insider input rather than simple aggregation.
low severity: The specific tradecraft breakdown and the detailed explanation of the telemetry setup feel grounded in real-world security research, though this cannot be confirmed without external context.
Human Indicators
Idiosyncratic emphasis on the technical flow and specific interaction methods (e.g., describing the path through COM & RPC) suggests a writer deeply immersed in this subject matter, rather than a pure summarizer.
The concluding narrative pivots clearly from adversary tradecraft to the vendor's internal response, characteristic of deep-dive security reporting.
Defender Exclusion Abuse: How Attackers Hide Malware from MDAV | Huntaegis