DefendNot is a Windows defense-evasion tool that abuses Windows Security Center antivirus-registration functionality to register a fraudulent antivirus product. This can cause Microsoft Defender to disable itself to avoid a perceived conflict with another security product. The tool has been associated with loading or injecting its payload into Task Manager and interacting with Windows Security Center antivirus-status interfaces. It can also be used alongside scheduled-task or autorun persistence mechanisms. DefendNot originated as a research tool demonstrating weaknesses in the Windows Security Center trust model, but has been repurposed in malware operations to neutralize Microsoft Defender before deployment of follow-on payloads. It has been observed in campaigns targeting Windows users and organizations in Russia, including operations delivering Amnesia RAT and Hakuna Matata-derived ransomware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
The content includes "Get-WmiObject -Namespace root\SecurityCenter2 -Class AntiVirusProduct."
The profile is intended to detect "scheduled-task persistence" and monitors "TaskCache\Tree" and "TaskCache\Tasks" plus the Task Scheduler TaskCache registry representation.
The profile is intended to detect "scheduled-task persistence" and monitors "TaskCache\Tree" and "TaskCache\Tasks" plus the Task Scheduler TaskCache registry representation.
Registry monitoring targets Security Center AV-provider keys, Windows Defender policy/configuration keys, and Task Scheduler TaskCache registry paths; Event IDs 4657 and 4663 are used to identify changes and access.
The profile is intended to detect "scheduled-task persistence" and monitors "TaskCache\Tree" and "TaskCache\Tasks" plus the Task Scheduler TaskCache registry representation.
The Sysmon profile is described as detecting "process injection" and specifically collects remote-thread creation, process access, and DLL-load events involving Taskmgr.exe. DefendNot strings identify "Taskmgr.exe" as the victim process and "defendnot.dll" as the DLL name.
Specific Logs for Detection Sysmon: Event ID 7 (Image Loaded into trusted processes), Event ID 8 (CreateRemoteThread), Event ID 10 (ProcessAccess). Process Data: Unexpected modules in legitimate processes (e.g., Taskmgr.exe ).
Register fake AV (Malicious Security Product) via IWscAvStatus Interface... The Windows Security Center processes the fraudulent registration request and accepts it as a legitimate security product (AV).
The Sysmon profile is described as detecting "process injection" and specifically collects remote-thread creation, process access, and DLL-load events involving Taskmgr.exe. DefendNot strings identify "Taskmgr.exe" as the victim process and "defendnot.dll" as the DLL name.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
DefendNot is a Windows tool that registers a signed fake antivirus product with Windows Security Center (WSC), causing Microsoft Defender to enter passive mode or otherwise reducing its active protections. The shown artifacts indicate use of WSC interfaces such as IWscAVStatus/RegisterAV/UpdateStatusAV, a loader executable, a DLL payload loaded into Task Manager, optional firewall-related operation, and scheduled-task persistence via TaskCache. It is intended to evade or disable Defender without directly relying solely on conventional Defender policy changes.
A payload deployed by MoiClient to attempt to disable Windows Defender after the backdoor obtains elevated privileges.
Tool used to disable Microsoft Defender as part of the attack chain to facilitate subsequent payload execution.
Tool used to help evade or disable Microsoft Defender scanning as part of the attack chain.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.