Skip to content

Security1 publisher2 min readPublished Updated

Attackers hide malware from Microsoft Defender by adding scan exclusions

Huntress details four ways attackers who already hold administrator rights add Microsoft Defender exclusions to keep malicious files out of every scan. A registry value can also hide those exclusions from any admin who checks for them.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Attackers hide malware from Microsoft Defender by adding scan exclusions
Generated illustration

What happened

  • Path and extension exclusions pull any matching file or process out of Defender's scheduled scans, on-demand scans and real-time protection.
  • WhisperGate used PowerShell's Set-MpPreference to exclude the entire C:\ drive from Defender in 2022, the broadest of the documented cases.
  • Defender locks its own exclusions key against direct writes, so attackers edit the writable Group Policy Policies key, which applies after a reboot.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure An intruder already at admin can blind Defender on chosen paths while the engine keeps reporting healthy, so no disabled-antivirus alert ever fires.
  • capability A registry value lets attackers hide the exclusions from admins who list them, so reading the current config cannot confirm the host is clean.
  • decision A query returns both the Defender and Group Policy sets and entries can be hidden, so auditing the resulting list misses them. Defenders have to alert on writes to both registry keys.
  • precedent A supported Windows feature abused the same way from 2019 to 2024 is standard post-exploitation tradecraft.

Everything here starts after the attacker already holds administrator rights. Microsoft exposes exclusions as a supported feature, and a user at administrator level or higher can tell Defender to skip folders, binaries, and IP addresses [2]. Turning Defender off outright trips the obvious alarm [3]. Adding a path exclusion leaves the engine running and reporting healthy while anything in that path escapes scheduled scans, on-demand scans, and real-time protection [9].

A PowerShell exclusion routes through the MSFT_MpPreference WMI class, then COM and RPC, and ends at MsMpEng.exe, which writes to HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions [6]. A Group Policy exclusion lands elsewhere: the gpsvc service writes to HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions [7]. A query against Defender returns both sets at once [8]. Microsoft locks the first key against direct writes, so Huntress says an attacker edits the Paths value under the Policies key instead, and that change needs a reboot to apply [13][14].

Huntress also found a registry value an attacker can set to hide exclusions from an administrator who queries them [15]. List the exclusions and nothing shows. The write to the key is the event to catch, so Huntress built its coverage around telemetry on these settings [16].

The technique has been in use for five years, from GootKit to Muddled Libra [1]. GootKit added a path exclusion through the WMI class in 2019 [10]. WhisperGate excluded the entire C:\ drive via Set-MpPreference in 2022 [11]. Huntress lists Muddled Libra using the technique in 2024 [12].

What to watch

  • Whether Microsoft tightens exclusion changes beyond a local admin token or extends tamper protection to the Policies key.
  • Whether the hidden-exclusion registry value is picked up in EDR detections and published hunt rules.
  • New campaigns adopting the Policies-key edit, which survives Defender's lockdown of its own exclusions key.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories