{"id":3888,"date":"2025-05-12T10:03:45","date_gmt":"2025-05-12T10:03:45","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/05\/12\/defendnot-a-new-tool-that-disables-windows-defender-by-posing-as-an-antivirus-solution\/"},"modified":"2025-05-12T10:03:45","modified_gmt":"2025-05-12T10:03:45","slug":"defendnot-a-new-tool-that-disables-windows-defender-by-posing-as-an-antivirus-solution","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/05\/12\/defendnot-a-new-tool-that-disables-windows-defender-by-posing-as-an-antivirus-solution\/","title":{"rendered":"Defendnot \u2014 A New Tool That Disables Windows Defender by Posing as an Antivirus Solution"},"content":{"rendered":"<p>    Defendnot \u2014 A New Tool That Disables Windows Defender by Posing as an Antivirus Solution<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Defendnot, a sophisticated new tool that effectively disables Windows Defender by exploiting the Windows Security Center (WSC) API to register itself as a legitimate antivirus solution.\u00a0<\/p>\n<p>The Windows Security Center service is designed to ensure Windows computers maintain adequate security protection.\u00a0<\/p>\n<p>When third-party <a href=\"https:\/\/cybersecuritynews.com\/the-role-of-antivirus-software-in-keeping-your-computer-safe\/\" target=\"_blank\" rel=\"noreferrer noopener\">antivirus software<\/a> is installed, it registers with WSC, which then automatically disables Windows Defender to prevent conflicts.<\/p>\n<p>Developed by a GitHub developer known as \u201ces3n1n\u201d, the tool is noteworthy for its direct interaction with WSC without relying on code from existing antivirus products.<\/p>\n<p>This release comes approximately one year after the developer\u2019s previous tool, \u201cno-defender,\u201d was removed following a DMCA takedown request.<\/p>\n<p>\u201cThere\u2019s a WSC (Windows Security Center) service in Windows which is used by antiviruses to let Windows know that there\u2019s some other antivirus in the hood and it should disable Windows Defender,\u201d the developer shared in a <a href=\"https:\/\/blog.es3n1n.eu\/posts\/how-i-ruined-my-vacation\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">report<\/a> with Cyber Security News.\u00a0<\/p>\n<p>\u201cThis WSC API is undocumented and furthermore requires people to sign an NDA with Microsoft to get its documentation.\u201d<\/p>\n<h2 class=\"wp-block-heading\">\n<strong>Defendnot<\/strong> <strong>Disable Windows Defender<\/strong><br \/>\n<\/h2>\n<p>According to the developer\u2019s detailed blog post, creating defendnot involved extensive reverse engineering of the WSC service and identifying the process validation mechanisms Microsoft employs.\u00a0<\/p>\n<p>The project faced significant technical challenges, including understanding how WSC validates calling processes before allowing them to register as antivirus solutions.<\/p>\n<p>A critical discovery was that WSC performs checks on processes attempting to register, including verifying the IMAGE_DLLCHARACTERISTICS_FORCE_INTEGRITY flag in the PE header and examining digital signatures.\u00a0<\/p>\n<p>The Task Manager (Taskmgr.exe) met these requirements and could be used as a \u201cvictim process\u201d to host the defendnot code.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXf70dWboPS_Ykd-5XbYz5nk8x3dwbh0NUmhRgV6xnH93CehY9cuTOKoufc3lOenoWwK2P5B381MMwpdjGMbM5sD5ri0lIZR36UnKEIcZLy2Fu6NNlGkYes_Ls2RsNRzEkK1iQyuaA?key=0BNoEev6JG98uaaa0QBStQ\" alt=\"\"><\/figure>\n<\/div>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXcW_BpcXOx6J227KvMA2z9UxLn1Y2R7Ke7IYvpbfEfC_4fy4HcURL_o-009Ti1pZafOfoMj4czxwhhHcir-5QH9bX6ne3QRw1qt5fRMTM14TJFTcQP3uz978ExNIctmKYEEyqFjBQ?key=0BNoEev6JG98uaaa0QBStQ\" alt=\"\"><\/figure>\n<\/div>\n<p>The tool uses COM interfaces to interact with WSC, registering a phantom antivirus product. When Windows detects this \u201cantivirus,\u201d it automatically disables its built-in protection.\u00a0<\/p>\n<p>Security researcher Will Dormann highlighted the tool on social media, noting that it \u201cuses this technique to install a null AV product, thus having the effect of simply disabling <a href=\"https:\/\/cybersecuritynews.com\/tag\/microsoft-defender\/\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Defender<\/a>.\u201d<\/p>\n<p>Technically, defendnot implements interfaces such as IWSCProductList to interact with WSC and utilizes undocumented <a href=\"https:\/\/cybersecuritynews.com\/ako-ransomware-abusing-windows-api-calls\/\" target=\"_blank\" rel=\"noreferrer noopener\">Windows API<\/a>s that Microsoft typically only shares with certified antivirus vendors through their Microsoft Virus Initiative (MVI) program under NDA.<\/p>\n<p>The tool includes several commands:<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXd05dWYdAZq-xO5fr-8ROXlkCSA0BP-4hGk1LqlhHFmM7kSZfwQuBGlwp9XTDw3vJBH9f2xK2s25_T2Wu7-qzSIjtkhv5N1-iNlm-YYahDDO-7QReIjM-tL5-JqVUOOybF1H8sNEw?key=0BNoEev6JG98uaaa0QBStQ\" alt=\"\"><\/figure>\n<\/div>\n<p>One limitation noted by the developer is that \u201cto keep this WSC stuff even after reboot, defendnot adds itself to the autorun. Thus, you would need to keep the defendnot binaries on your disk.\u201d<\/p>\n<p>While the tool demonstrates impressive technical knowledge and <a href=\"https:\/\/cybersecuritynews.com\/tag\/reverse-engineering\/\" target=\"_blank\" rel=\"noreferrer noopener\">reverse engineering<\/a> skills, security experts caution that such utilities could potentially be misused by malware authors seeking to disable security protections.\u00a0<\/p>\n<p>However, it\u2019s worth noting that defendnot requires administrative privileges to function, limiting its potential for covert deployment.<\/p>\n<p>For security researchers and administrators, this tool provides valuable insights into how Windows manages security product integration and highlights potential areas where Microsoft\u2019s security architecture could be strengthened to prevent similar bypasses in the future.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong><strong>Setting Up SOC Team? \u2013 Download Free Ultimate SIEM Pricing Guide (PDF) For Your SOC Team -&gt;\u00a0<\/strong><\/strong><a href=\"https:\/\/underdefense.com\/ultimate-managed-siem-pricing-guide\/?utm_source=gbhackers&amp;utm_medium=online_media&amp;utm_campaign=gbh_eblast_managed_siem_pricing\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>Free Download<\/strong><\/a><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/defendnot-disables-windows-defender\/\">Defendnot \u2014 A New Tool That Disables Windows Defender by Posing as an Antivirus Solution<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/defendnot-disables-windows-defender\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Defendnot \u2014 A New Tool That Disables Windows Defender by Posing as an Antivirus Solution Defendnot, a sophisticated new tool that effectively disables Windows Defender by exploiting the Windows Security Center (WSC) API to register itself as a legitimate antivirus solution.\u00a0 The Windows Security Center service is designed to ensure Windows computers maintain adequate security [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,395],"tags":[130],"class_list":["post-3888","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-windows","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/3888"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=3888"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/3888\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=3888"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=3888"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=3888"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}