Sunday, May 18, 2025
HomeTechnologyNew 'Defendnot' device methods Home windows into disabling Microsoft Defender

New ‘Defendnot’ device methods Home windows into disabling Microsoft Defender

New ‘Defendnot’ device methods Home windows into disabling Microsoft Defender

A brand new device referred to as ‘Defendnot’ can disable Microsoft Defender on Home windows units by registering a pretend antivirus product, even when no actual AV is put in.

The trick makes use of an undocumented Home windows Safety Middle (WSC) API that antivirus software program makes use of to inform Home windows it’s put in and is now managing the real-time safety for the gadget.

When an antivirus program is registered, Home windows routinely disables Microsoft Defender to keep away from conflicts from operating a number of safety purposes on the identical gadget.

The Defendnot device, created by researcher es3n1n, abuses this API by registering a pretend antivirus product that meets all of Home windows’ validation checks.

The device relies on a earlier mission referred to as no-defender, which used code from a third-party antivirus product to spoof registration with WSC. That earlier device was pulled from GitHub after the seller filed a DMCA takedown.

“Then, after just a few weeks after the discharge, the mission blew up fairly a bit and gained ~1.5k stars, after that the builders of the antivirus I used to be utilizing filed a DMCA takedown request and I did not actually wish to do something with that so simply erased every little thing and referred to as it a day,” the developer explains in a weblog submit.

Defendnot avoids copyright points by constructing the performance from scratch by way of a dummy antivirus DLL.

Usually, WSC API is safeguarded by way of Protected Course of Mild (PPL), legitimate digital signatures, and different options.

To bypass these necessities, Defendnot injects its DLL right into a system course of, Taskmgr.exe, that’s signed and already trusted by Microsoft. From inside that course of, it might probably register the dummy antivirus with a spoofed show title.

As soon as registered, Microsoft Defender instantly shuts itself off, leaving no energetic safety on the gadget.

Defendnot registered on a device
Defendnot registered on a tool
Supply: BleepingComputer

The device additionally features a loader that passes configuration information through a ctx.bin file and allows you to set the antivirus title you wish to use, flip off registration, and allow verbose logging.

For persistence, Defendnot creates an autorun by way of the Home windows Activity Scheduler in order that it begins once you log in to Home windows.

Whereas Defendnot is taken into account a analysis mission, the device demonstrates how trusted system options will be manipulated to show off security measures.

Microsoft Defender is at the moment detecting and quarantining Defendnot as a ‘Win32/Sabsik.FL.!ml; detection.

Primarily based on an evaluation of 14M malicious actions, uncover the highest 10 MITRE ATT&CK strategies behind 93% of assaults and the best way to defend towards them.

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular

Recent Comments