[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fVlx6rabrTlOc4BTN3wJurv7nSFcaSZ_rbsUJkcQAT4Y":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},1181,"What is the token removal technique to disable Windows Defender, and what are its requirements?","The token removal technique exploits the fact that the Windows Defender process (MsMpEng.exe) runs as a **Protected Process Light (PPL)**. By using a thread with **SYSTEM privileges**, an attacker can remove all tokens from MsMpEng.exe, preventing it from accessing other process resources and thus disabling its detection capabilities. This method requires SYSTEM privileges and is demonstrated by tools like KillDefender. Defenses include using tools such as [PPLGuard](https:\u002F\u002Fgithub.com\u002Felastic\u002FPPLGuard) to block non-PPL processes from modifying PPL tokens. See the [Penetration Basics - Windows Defender](\u002Fnews\u002Fpenetration-basics-windows-defender) article for the full POC reference and defense recommendations.","\u003Cp>The token removal technique exploits the fact that the Windows Defender process (MsMpEng.exe) runs as a **Protected Process Light (PPL)**. By using a thread with **SYSTEM privileges**, an attacker can remove all tokens from MsMpEng.exe, preventing it from accessing other process resources and thus disabling its detection capabilities. This method requires SYSTEM privileges and is demonstrated by tools like KillDefender. Defenses include using tools such as [PPLGuard](https:\u002F\u002Fgithub.com\u002Felastic\u002FPPLGuard) to block non-PPL processes from modifying PPL tokens. See the [Penetration Basics - Windows Defender](\u002Fnews\u002Fpenetration-basics-windows-defender) article for the full POC reference and defense recommendations.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-basics-windows-defender\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-the-token-removal-technique-to-disable-windows-defender-and-what-are-its-1777480172453","token removal, PPL, SYSTEM privileges, MsMpEng.exe, KillDefender, PPLGuard",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},286,"Penetration Basics - Windows Defender","penetration-basics-windows-defender","Learn penetration techniques for Windows Defender: disable real-time protection, manage exclusions, bypass tamper protection, and restore quarantined files with commands.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Windows Defender is an antivirus software program built into the Windows operating system. This article introduces penetration methods related to Windows Defender solely from a technical research perspective, analyzes exploitation approaches, and provides defense recommendations.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Check Windows Defender Version\u003C\u002Fli>\u003Cli>View Existing Exclusion List\u003C\u002Fli>\u003Cli>Disable Windows Defender Real-time Protection\u003C\u002Fli>\u003Cli>Add Exclusion List\u003C\u002Fli>\u003Cli>Remove Token to Disable Windows Defender\u003C\u002Fli>\u003Cli>Restore Quarantined Files\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Check Windows Defender Version\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. View via Panel\u003C\u002Fh3>\u003Cp>Navigate to Windows Security -&gt; Settings -&gt; About, where Antimalware Client Version indicates the Windows Defender version, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016715151_0_1daab84a31.jpeg\">\u003C\u002Fp>\u003Ch3>2. View via Command Line\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dir \"C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\\" \u002Fod \u002Fad \u002Fb\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The larger number indicates the latest version\u003C\u002Fp>\u003Ch2>0x03 View Existing Exclusion List\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. View via Panel\u003C\u002Fh3>\u003Cp>Navigate to Windows Security -&gt; Virus &amp; threat protection settings -&gt; Add or remove exclusions, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016718027_1_2357fbd1df.jpeg\">\u003C\u002Fp>\u003Ch3>2. View via Command Line\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg query \"HKLM\\SOFTWARE\\Microsoft\\Windows Defender\\Exclusions\" \u002Fs\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. View via PowerShell\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-MpPreference | select ExclusionPath\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Disable Windows Defender Real-time Protection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Disable via Control Panel\u003C\u002Fh3>\u003Cp>Navigate to Windows Security -&gt; Virus &amp; threat protection settings, turn off Real-time protection\u003C\u002Fp>\u003Ch3>2. Disable via Command Line\u003C\u002Fh3>\u003Cp>Prerequisites:\u003C\u002Fp>\u003Cul>\u003Cli>Requires TrustedInstaller privileges\u003C\u002Fli>\u003Cli>Tamper Protection must be disabled\u003C\u002Fli>\u003C\u002Ful>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows Defender\\Real-Time Protection\" \u002Fv \"DisableRealtimeMonitoring\" \u002Fd 1 \u002Ft REG_DWORD \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>When successful, a notification will pop up in the bottom-right corner indicating Windows Defender has been disabled\u003C\u002Fp>\u003Ch3>Supplement 1: Enable Windows Defender Real-time Protection\u003C\u002Fh3>\u003Cp>Prerequisites:\u003C\u002Fp>\u003Cul>\u003Cli>Requires TrustedInstaller privileges\u003C\u002Fli>\u003Cli>Tamper Protection must be disabled\u003C\u002Fli>\u003C\u002Ful>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg delete \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows Defender\\Real-Time Protection\" \u002Fv \"DisableRealtimeMonitoring\" \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Supplement 2: Obtain TrustedInstaller privileges\u003C\u002Fh3>\u003Cp>Refer to the previous article \"Penetration Techniques - Token Theft and Exploitation\"\u003C\u002Fp>\u003Cp>You can also use AdvancedRun, command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>AdvancedRun.exe \u002FEXEFilename \"%windir%\\system32\\cmd.exe\" \u002FCommandLine '\u002Fc reg add \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows Defender\\Real-Time Protection\" \u002Fv \"DisableRealtimeMonitoring\" \u002Fd 1 \u002Ft REG_DWORD \u002Ff' \u002FRunAs 8 \u002FRun\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Supplement 3: Tamper Protection\u003C\u002Fh3>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fmicrosoft-365\u002Fsecurity\u002Fdefender-endpoint\u002Fprevent-changes-to-security-settings-with-tamper-protection?view=o365-worldwide\u003C\u002Fp>\u003Cp>When Tamper Protection is enabled, users cannot modify Windows Defender configurations via registry, PowerShell, or group policy\u003C\u002Fp>\u003Cp>Method to enable Tamper Protection:\u003C\u002Fp>\u003Cp>Select Windows Security -&gt; Virus &amp; threat protection settings in sequence, then enable Tamper Protection\u003C\u002Fp>\u003Cp>Corresponding cmd command for this operation: reg add \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows Defender\\Features\" \u002Fv \"TamperProtection\" \u002Fd 5 \u002Ft REG_DWORD \u002Ff\u003C\u002Fp>\u003Cp>Method to disable Tamper Protection:\u003C\u002Fp>\u003Cp>Select Windows Security -&gt; Virus &amp; threat protection settings in sequence, then disable Tamper Protection\u003C\u002Fp>\u003Cp>Corresponding cmd command for this operation: reg add \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows Defender\\Features\" \u002Fv \"TamperProtection\" \u002Fd 4 \u002Ft REG_DWORD \u002Ff. However, we cannot set Tamper Protection by modifying the registry; it can only be changed through the panel\u003C\u002Fp>\u003Cp>Check the status of Tamper Protection:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg query \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows Defender\\Features\" \u002Fv \"TamperProtection\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>In the returned result, a value of 5 indicates enabled, and a value of 4 indicates disabled\u003C\u002Fp>\u003Ch3>Supplement 4: Disable Windows Defender's Real-time protection via PowerShell\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Set-MpPreference -DisableRealtimeMonitoring $true\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note: This is no longer applicable in newer versions of Windows\u003C\u002Fstrong>\u003C\u002Fp>\u003Ch3>Supplement 5: Disable Windows Defender's Real-time protection via Group Policy\u003C\u002Fh3>\u003Cp>Open gpedit.msc in sequence -&gt; Computer Configuration -&gt; Administrative Templates -&gt; Windows Components -&gt; Microsoft Defender Antivirus -&gt; Real-time Protection, select Turn off real-time protection, and configure it as Enable\u003C\u002Fp>\u003Cp>\u003Cstrong>Note: This is no longer applicable in newer versions of Windows\u003C\u002Fstrong>\u003C\u002Fp>\u003Ch2>0x05 Add Scan Exclusion List\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Add via Panel\u003C\u002Fh3>\u003Cp>Select Windows Security -&gt; Virus &amp; threat protection settings -&gt; Add or remove exclusions in sequence, choose Add an exclusion, and specify the type\u003C\u002Fp>\u003Cp>This operation is equivalent to modifying the registry key values at HKLM\\SOFTWARE\\Microsoft\\Windows Defender\\Exclusions\\, with specific locations as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Type File corresponds to the registry entry Paths\u003C\u002Fli>\u003Cli>The type Folder corresponds to the registry key Paths\u003C\u002Fli>\u003Cli>The type File type corresponds to the registry key Extensions\u003C\u002Fli>\u003Cli>The type Process corresponds to the registry key Processes\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>2. Adding via command line\u003C\u002Fh3>\u003Cp>Prerequisites:\u003C\u002Fp>\u003Cul>\u003Cli>Requires TrustedInstaller permissions\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Example cmd command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows Defender\\Exclusions\\Paths\" \u002Fv \"c:\\test\" \u002Fd 0 \u002Ft REG_DWORD \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Adding via PowerShell\u003C\u002Fh3>\u003Cp>Prerequisites:\u003C\u002Fp>\u003Cul>\u003Cli>Requires administrator permissions\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fpowershell\u002Fmodule\u002Fdefender\u002Fadd-mppreference?view=windowsserver2022-ps\u003C\u002Fp>\u003Cp>Example PowerShell command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Add-MpPreference -ExclusionPath \"C:\\test\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Note: Delete exclusion list\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Remove-MpPreference -ExclusionPath \"C:\\test\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x06 Removing Token Causes Windows Defender to Fail\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Learning address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Felastic.github.io\u002Fsecurity-research\u002Fwhitepapers\u002F2022\u002F02\u002F02.sandboxing-antimalware-products-for-fun-and-profit\u002Farticle\u002F\u003C\u002Fp>\u003Cp>Simple understanding:\u003C\u002Fp>\u003Cul>\u003Cli>The Windows Defender process is MsMpEng.exe\u003C\u002Fli>\u003Cli>MsMpEng.exe is a protected process (Protected Process Light, abbreviated as PPL)\u003C\u002Fli>\u003Cli>Non-PPL processes cannot obtain handles to PPL processes, preventing us from directly terminating the PPL process MsMpEng.exe\u003C\u002Fli>\u003Cli>However, we can modify the token of the process MsMpEng.exe using threads running with SYSTEM privileges\u003C\u002Fli>\u003Cli>After removing all tokens from the process MsMpEng.exe, the process cannot access resources of other processes, thus unable to detect whether other processes are malicious, ultimately causing Windows Defender to fail\u003C\u002Fli>\u003C\u002Ful>\u003Cp>POC address: https:\u002F\u002Fgithub.com\u002Fpwn1sher\u002FKillDefender\u003C\u002Fp>\u003Cp>Exploitation conditions:\u003C\u002Fp>\u003Cul>\u003Cli>Requires System privileges\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016724369_2_1c197a79f3.jpeg\">\u003C\u002Fp>\u003Ch2>0x07 Restore Quarantined Files\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fmicrosoft-365\u002Fsecurity\u002Fdefender-endpoint\u002Fcommand-line-arguments-microsoft-defender-antivirus?view=o365-worldwide\u003C\u002Fp>\u003Ch3>1. Locate MpCmdRun\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dir \"C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\\" \u002Fod \u002Fad \u002Fb\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Obtain \u003Cantimalware platform=\"\" version=\"\">\u003C\u002Fantimalware>\u003C\u002Fp>\u003Cp>Location of MpCmdRun: C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\\u003Cantimalware platform=\"\" version=\"\">\u003C\u002Fantimalware>\u003C\u002Fp>\u003Ch3>2. Common Commands\u003C\u002Fh3>\u003Cp>View list of quarantined files:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>MpCmdRun -Restore -ListAll\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Restore file with specified name to original directory:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>MpCmdRun -Restore -FilePath C:\\test\\mimikatz_trunk.zip\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Restore all files to original directory:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>MpCmdRun -Restore -All\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Check if specified path is in exclusion list:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>MpCmdRun -CheckExclusion -path C:\\test\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x08 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Prevent command-line shutdown of Windows Defender: Enable Tamper Protection\u003C\u002Fp>\u003Cp>Prevent Windows Defender failure via token removal: Block non-PPL processes from modifying token of PPL process MsMpEng.exe. Tool reference: https:\u002F\u002Fgithub.com\u002Felastic\u002FPPLGuard\u003C\u002Fp>\u003Ch2>0x09 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces Windows Defender-related penetration methods solely from a technical research perspective, analyzes exploitation approaches, and provides defense recommendations. The exploitation method causing Windows Defender failure via token removal may be resolved by default in future Windows versions.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Windows Defender is an antivirus software program built into the Windows operating system. This article introduces penetration methods related to Windows Defender solely from a technical research perspective, analyzes exploitation approaches, and provides defense recommendations.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Check Windows Defender Version\u003C\u002Fli>\u003Cli>View Existing Exclusion List\u003C\u002Fli>\u003Cli>Disable Windows Defender Real-time Protection\u003C\u002Fli>\u003Cli>Add Exclusion List\u003C\u002Fli>\u003Cli>Remove Token to Disable Windows Defender\u003C\u002Fli>\u003Cli>Restore Quarantined Files\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Check Windows Defender Version\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. View via Panel\u003C\u002Fh3>\u003Cp>Navigate to Windows Security -&gt; Settings -&gt; About, where Antimalware Client Version indicates the Windows Defender version, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016715151_0_1daab84a31-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. View via Command Line\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dir \"C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\\" \u002Fod \u002Fad \u002Fb\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The larger number indicates the latest version\u003C\u002Fp>\u003Ch2>0x03 View Existing Exclusion List\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. View via Panel\u003C\u002Fh3>\u003Cp>Navigate to Windows Security -&gt; Virus &amp; threat protection settings -&gt; Add or remove exclusions, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016718027_1_2357fbd1df-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. View via Command Line\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg query \"HKLM\\SOFTWARE\\Microsoft\\Windows Defender\\Exclusions\" \u002Fs\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. View via PowerShell\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-MpPreference | select ExclusionPath\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Disable Windows Defender Real-time Protection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Disable via Control Panel\u003C\u002Fh3>\u003Cp>Navigate to Windows Security -&gt; Virus &amp; threat protection settings, turn off Real-time protection\u003C\u002Fp>\u003Ch3>2. Disable via Command Line\u003C\u002Fh3>\u003Cp>Prerequisites:\u003C\u002Fp>\u003Cul>\u003Cli>Requires TrustedInstaller privileges\u003C\u002Fli>\u003Cli>Tamper Protection must be disabled\u003C\u002Fli>\u003C\u002Ful>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows Defender\\Real-Time Protection\" \u002Fv \"DisableRealtimeMonitoring\" \u002Fd 1 \u002Ft REG_DWORD \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>When successful, a notification will pop up in the bottom-right corner indicating Windows Defender has been disabled\u003C\u002Fp>\u003Ch3>Supplement 1: Enable Windows Defender Real-time Protection\u003C\u002Fh3>\u003Cp>Prerequisites:\u003C\u002Fp>\u003Cul>\u003Cli>Requires TrustedInstaller privileges\u003C\u002Fli>\u003Cli>Tamper Protection must be disabled\u003C\u002Fli>\u003C\u002Ful>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg delete \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows Defender\\Real-Time Protection\" \u002Fv \"DisableRealtimeMonitoring\" \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Supplement 2: Obtain TrustedInstaller privileges\u003C\u002Fh3>\u003Cp>Refer to the previous article \"Penetration Techniques - Token Theft and Exploitation\"\u003C\u002Fp>\u003Cp>You can also use AdvancedRun, command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>AdvancedRun.exe \u002FEXEFilename \"%windir%\\system32\\cmd.exe\" \u002FCommandLine '\u002Fc reg add \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows Defender\\Real-Time Protection\" \u002Fv \"DisableRealtimeMonitoring\" \u002Fd 1 \u002Ft REG_DWORD \u002Ff' \u002FRunAs 8 \u002FRun\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Supplement 3: Tamper Protection\u003C\u002Fh3>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fmicrosoft-365\u002Fsecurity\u002Fdefender-endpoint\u002Fprevent-changes-to-security-settings-with-tamper-protection?view=o365-worldwide\u003C\u002Fp>\u003Cp>When Tamper Protection is enabled, users cannot modify Windows Defender configurations via registry, PowerShell, or group policy\u003C\u002Fp>\u003Cp>Method to enable Tamper Protection:\u003C\u002Fp>\u003Cp>Select Windows Security -&gt; Virus &amp; threat protection settings in sequence, then enable Tamper Protection\u003C\u002Fp>\u003Cp>Corresponding cmd command for this operation: reg add \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows Defender\\Features\" \u002Fv \"TamperProtection\" \u002Fd 5 \u002Ft REG_DWORD \u002Ff\u003C\u002Fp>\u003Cp>Method to disable Tamper Protection:\u003C\u002Fp>\u003Cp>Select Windows Security -&gt; Virus &amp; threat protection settings in sequence, then disable Tamper Protection\u003C\u002Fp>\u003Cp>Corresponding cmd command for this operation: reg add \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows Defender\\Features\" \u002Fv \"TamperProtection\" \u002Fd 4 \u002Ft REG_DWORD \u002Ff. However, we cannot set Tamper Protection by modifying the registry; it can only be changed through the panel\u003C\u002Fp>\u003Cp>Check the status of Tamper Protection:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg query \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows Defender\\Features\" \u002Fv \"TamperProtection\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>In the returned result, a value of 5 indicates enabled, and a value of 4 indicates disabled\u003C\u002Fp>\u003Ch3>Supplement 4: Disable Windows Defender's Real-time protection via PowerShell\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Set-MpPreference -DisableRealtimeMonitoring $true\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note: This is no longer applicable in newer versions of Windows\u003C\u002Fstrong>\u003C\u002Fp>\u003Ch3>Supplement 5: Disable Windows Defender's Real-time protection via Group Policy\u003C\u002Fh3>\u003Cp>Open gpedit.msc in sequence -&gt; Computer Configuration -&gt; Administrative Templates -&gt; Windows Components -&gt; Microsoft Defender Antivirus -&gt; Real-time Protection, select Turn off real-time protection, and configure it as Enable\u003C\u002Fp>\u003Cp>\u003Cstrong>Note: This is no longer applicable in newer versions of Windows\u003C\u002Fstrong>\u003C\u002Fp>\u003Ch2>0x05 Add Scan Exclusion List\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Add via Panel\u003C\u002Fh3>\u003Cp>Select Windows Security -&gt; Virus &amp; threat protection settings -&gt; Add or remove exclusions in sequence, choose Add an exclusion, and specify the type\u003C\u002Fp>\u003Cp>This operation is equivalent to modifying the registry key values at HKLM\\SOFTWARE\\Microsoft\\Windows Defender\\Exclusions\\, with specific locations as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Type File corresponds to the registry entry Paths\u003C\u002Fli>\u003Cli>The type Folder corresponds to the registry key Paths\u003C\u002Fli>\u003Cli>The type File type corresponds to the registry key Extensions\u003C\u002Fli>\u003Cli>The type Process corresponds to the registry key Processes\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>2. Adding via command line\u003C\u002Fh3>\u003Cp>Prerequisites:\u003C\u002Fp>\u003Cul>\u003Cli>Requires TrustedInstaller permissions\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Example cmd command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows Defender\\Exclusions\\Paths\" \u002Fv \"c:\\test\" \u002Fd 0 \u002Ft REG_DWORD \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Adding via PowerShell\u003C\u002Fh3>\u003Cp>Prerequisites:\u003C\u002Fp>\u003Cul>\u003Cli>Requires administrator permissions\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fpowershell\u002Fmodule\u002Fdefender\u002Fadd-mppreference?view=windowsserver2022-ps\u003C\u002Fp>\u003Cp>Example PowerShell command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Add-MpPreference -ExclusionPath \"C:\\test\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Note: Delete exclusion list\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Remove-MpPreference -ExclusionPath \"C:\\test\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x06 Removing Token Causes Windows Defender to Fail\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Learning address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Felastic.github.io\u002Fsecurity-research\u002Fwhitepapers\u002F2022\u002F02\u002F02.sandboxing-antimalware-products-for-fun-and-profit\u002Farticle\u002F\u003C\u002Fp>\u003Cp>Simple understanding:\u003C\u002Fp>\u003Cul>\u003Cli>The Windows Defender process is MsMpEng.exe\u003C\u002Fli>\u003Cli>MsMpEng.exe is a protected process (Protected Process Light, abbreviated as PPL)\u003C\u002Fli>\u003Cli>Non-PPL processes cannot obtain handles to PPL processes, preventing us from directly terminating the PPL process MsMpEng.exe\u003C\u002Fli>\u003Cli>However, we can modify the token of the process MsMpEng.exe using threads running with SYSTEM privileges\u003C\u002Fli>\u003Cli>After removing all tokens from the process MsMpEng.exe, the process cannot access resources of other processes, thus unable to detect whether other processes are malicious, ultimately causing Windows Defender to fail\u003C\u002Fli>\u003C\u002Ful>\u003Cp>POC address: https:\u002F\u002Fgithub.com\u002Fpwn1sher\u002FKillDefender\u003C\u002Fp>\u003Cp>Exploitation conditions:\u003C\u002Fp>\u003Cul>\u003Cli>Requires System privileges\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016724369_2_1c197a79f3-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x07 Restore Quarantined Files\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fmicrosoft-365\u002Fsecurity\u002Fdefender-endpoint\u002Fcommand-line-arguments-microsoft-defender-antivirus?view=o365-worldwide\u003C\u002Fp>\u003Ch3>1. Locate MpCmdRun\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dir \"C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\\" \u002Fod \u002Fad \u002Fb\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Obtain \u003Cantimalware platform=\"\" version=\"\">\u003C\u002Fantimalware>\u003C\u002Fp>\u003Cp>Location of MpCmdRun: C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\\u003Cantimalware platform=\"\" version=\"\">\u003C\u002Fantimalware>\u003C\u002Fp>\u003Ch3>2. Common Commands\u003C\u002Fh3>\u003Cp>View list of quarantined files:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>MpCmdRun -Restore -ListAll\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Restore file with specified name to original directory:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>MpCmdRun -Restore -FilePath C:\\test\\mimikatz_trunk.zip\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Restore all files to original directory:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>MpCmdRun -Restore -All\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Check if specified path is in exclusion list:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>MpCmdRun -CheckExclusion -path C:\\test\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x08 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Prevent command-line shutdown of Windows Defender: Enable Tamper Protection\u003C\u002Fp>\u003Cp>Prevent Windows Defender failure via token removal: Block non-PPL processes from modifying token of PPL process MsMpEng.exe. Tool reference: https:\u002F\u002Fgithub.com\u002Felastic\u002FPPLGuard\u003C\u002Fp>\u003Ch2>0x09 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces Windows Defender-related penetration methods solely from a technical research perspective, analyzes exploitation approaches, and provides defense recommendations. The exploitation method causing Windows Defender failure via token removal may be resolved by default in future Windows versions.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",37,"Onedaysec",4,"published","2026-02-02T07:25:19.685Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Windows Defender Penetration: Disable, Exclusions & Tamper Protection","Windows Defender penetration, disable real-time protection, exclusion list, tamper protection, TrustedInstaller, registry commands, PowerShell, security bypass",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45,46],1180,1179,1178,{"title":39,"description":39,"image":39},"2026-07-24T15:37:09.071Z","2026-07-23T16:02:38.985Z","draft","2026-07-23T16:17:14.091Z"]