Attackers are modifying Microsoft Defender Antivirus exclusion settings to prevent malware from being scanned while leaving Defender enabled, evading real-time, scheduled, and on-demand protections. The technique requires administrator-level access and can be deployed through PowerShell, WMI, Group Policy, or direct policy-registry changes; broad path or file-extension exclusions can shield malware staging locations and payloads. Huntress linked the behavior to activity involving GootKit, WhisperGate, and Muddled Libra.
Defender policies can conceal configured exclusions from PowerShell queries, including those executed as SYSTEM, limiting the reliability of routine endpoint inspection. Security teams should monitor for newly created exclusions, especially exclusions covering entire drives, broad extensions, or staging directories, and investigate modifications to the HideExclusionsFromLocalAdmins policy. Incident responders should validate both local and Group Policy registry locations directly rather than relying solely on Defender or PowerShell output.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Huntress linked the use of Microsoft Defender Antivirus exclusions to Muddled Libra activity, reflecting continued use of the technique after attackers gain elevated access.
Huntress associated WhisperGate activity with Microsoft Defender exclusion abuse, including an exclusion for the full C:\ drive that could shield malware from scanning.
Huntress linked abuse of Microsoft Defender Antivirus exclusion settings for defense evasion to GootKit activity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.