A developer published Defendnot, a Windows tool that disables Microsoft Defender by registering itself with Windows Security Center (WSC) as if it were a legitimate third-party antivirus product. The accompanying write-up says the method was developed through reverse engineering of the undocumented WSC API, allowing Defender to stand down automatically when the fake product is recognized by the operating system.
The GitHub project includes PowerShell-based deployment and command-line options to enable, disable, and persist the tool through autorun, while noting important limits and detection details. The author states that Microsoft Defender detects the utility as VirTool:Win64/Defnot.A, installation may require real-time and tamper protection to be turned off, the technique does not work on Windows Server because WSC is not present there, and persistence across reboots depends on keeping the binaries on disk.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
A GitHub repository for Defendnot is published, providing code and instructions for disabling Microsoft Defender by registering through WSC as another antivirus product. The repository documents installation, persistence via autorun, platform limitations, and notes Microsoft Defender detects the tool as VirTool:Win64/Defnot.A.
A blog post describes reverse engineering the undocumented Windows Security Center API to register a fake antivirus product so Windows disables Microsoft Defender. The work is presented as the basis for the Defendnot approach and as a successor to an earlier no-defender implementation that relied on third-party antivirus code.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.