Two separate Windows-focused research writeups describe practical evasion techniques against Microsoft Defender/EDR. One demonstrates bypassing Defender’s signature-based detections by constructing suspicious strings (e.g., Invoke-Mimikatz) at runtime using PowerShell character encoding/concatenation ([char]NN), reporting reliable evasion in a fully updated Windows 10/11 environment with real-time protection and script scanning enabled.
A second report covers EDRStartupHinder, a newly released tool by researcher TwoSevenOneT that aims to prevent antivirus/EDR services from starting cleanly on boot (demonstrated against Defender on Windows 11 25H2). The technique uses a higher-priority Windows service and Bindlink redirection of a selected System32 DLL to a tampered (“corrupted”) copy so the protected EDR process (e.g., MsMpEng.exe, running as PPL) fails to load required dependencies and crashes at startup; the article notes operator requirements such as choosing a DLL not in KnownDLLs and identifying service group order via HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ServiceGroupOrder and tooling like Process Monitor/Process Explorer boot logs.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
A researcher published testing results claiming Windows Defender could be bypassed by constructing malicious strings such as "Invoke-Mimikatz" through PowerShell character-code encoding, avoiding signature-based detection. The same testing said more explicit AMSI tampering attempts were blocked, while other suspicious behaviors like RWX memory allocation were not detected or prevented.
Security researcher TwoSevenOneT released EDRStartupHinder, a tool that uses Windows Bindlink to prevent antivirus and EDR services from starting by redirecting critical System32 DLLs. The technique was demonstrated against Microsoft Defender on Windows 11 25H2 and relies on causing protected security processes to fail during startup.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.