Bypass Record

Disable or Modify Tools × Microsoft Defender Antivirus

A publicly-reported instance of Disable or Modify Tools bypassing Microsoft Defender Antivirus, recorded with its original source. Factual record; no assessment of any specific deployment.

Product
Microsoft Defender Antivirus
Technique
Disable or Modify Tools
MITRE ATT&CK
T1562.001
Confidence
High
Severity
High
Status
in the wild
Disclosed
2026-10-05
Config / version noted
Not stated

Provenance

Reported as

Attackers are configuring Microsoft Defender exclusions to hide malicious directories and file types

Mechanism

After gaining administrative privileges, attackers add exclusions for directories or file extensions in Microsoft Defender settings. This prevents Defender from scanning those locations, allowing malware to persist and execute without detection while the antivirus appears active.

Detection & mitigation

Monitor for changes to Defender exclusion lists via Event ID 5007 (Microsoft-Windows-Windows Defender/Operational) or registry keys under HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions. Alert on any exclusion additions, especially for suspicious paths or extensions, and enforce least privilege to limit admin access.

Disable or Modify Tools has also been recorded against

This is a record of a publicly-reported event, not an assessment of any specific organization's deployment. Detection and mitigation notes are drawn from the cited source. Where the source is silent, fields are omitted.