Defender Exclusion Abuse: How Attackers Hide Malware from MDAV

Huntress Version 1 original current

Imported from official source

See how attackers like GootKit and WhisperGate abuse Windows Defender exclusions to hide malware from AV scans — and how Huntress detects it.

This version

Version
1 of 1
Recorded
October 01, 2026 03:00
Change
Initial
Content hash
664ee2912bf61a66d5543f180709c8d3
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.