Defender Exclusion Abuse: How Attackers Hide Malware from MDAV

Imported from official source

Cybersecurity Classified by Officially

The endpoint team at Huntress is focused on providing telemetry and protections around real adversary threats. One thing we've noticed that's often overlooked is adversaries leveraging Microsoft Defender Antivirus (MDAV) settings to circumvent scans on their malicious binaries. Obviously, turning off Defender completely is ideal for adversaries, but the setting we’re going to discuss today is MDAV exclusions.

Exclusions are a capability that Microsoft has exposed. They allow a user with administrator privileges or higher to circumvent AV scans on folders, binaries, and IP addresses. Depending on the use case, an attacker can leverage Exclusions more stealthily than shutting the antivirus down completely.

Before we dive into the adversary tradecraft, let’s take a look into the internals of MDAV exclusions. Microsoft supports four types of Antivirus exclusions, which support different actions on the exclusions:

Disables real-time scanning on files that are opened by specific processes, i.e., specified (source) process is not scanned.

Excludes entire file paths from real-time/scheduled scans.

Disables real-time/scheduled/custom scans on certain file extensions.

Disables network packet inspection incoming from a certain IP.

There are a few different ways someone can interact with MDAV exclusions:

When someone sets an exclusion via PowerShell, the call execution goes through the MSFT_MpPreference WMI Class. Then it makes its way through COM & RPC to eventually transition execution to MsMpEng.exe (the MDAV binary). MsMpEng.exe then makes a registry modification to the HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions registry key.

If someone creates an exclusion via a GPO, the execution flow often goes through the GPO svchost (C:\Windows\system32\svchost.exe -k netsvcs -p -s gpsvc) which sets a registry value within the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions.

This is an extract. The publication continues at the source.

Read the original at the source: https://www.huntress.com/blog/you-can-run-but-you-cant-hide-defender-exclusions

Officially imported this from Huntress’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Huntress — imported from official source
Official source
https://www.huntress.com/blog/rss.xml RSS
Imported
October 01, 2026 03:00
Versions
1 recorded
Identity
https://www.huntress.com/blog/you-can-run-but-you-cant-hide-defender-exclusions

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.