HomeCyber BalkansHackers Conceal Microsoft Defender Exclusions from Administrators to Avoid Antivirus Detection

Hackers Conceal Microsoft Defender Exclusions from Administrators to Avoid Antivirus Detection

Published on

spot_img

Exploitation of Microsoft Defender Antivirus Exclusions by Threat Actors

In recent findings, cybersecurity researchers from Huntress have uncovered a troubling trend: threat actors are increasingly exploiting exclusions within Microsoft Defender Antivirus (MDAV) to proactively evade detection by endpoint scans. This trend poses significant risks as it allows malicious actors to operate stealthily, manipulating legitimate features of MDAV to maintain persistence within target systems.

At the core of this issue is a specific policy setting known as HideExclusionsFromLocalAdmins. This setting enables attackers to create a highly concealed route for evading defenses, keeping malicious files hidden from inspections that would typically be conducted by endpoint security systems. By combining extensive MDAV exclusions with this policy, adversaries manage to obscure their tracks while executing harmful activities undetected.

MDAV exclusions serve as legitimate tools for system administrators, designed to prevent performance bottlenecks or compatibility issues with trusted software applications. These exclusions can cover various elements, including specific processes, file paths, file extensions, or even IP addresses from particular antivirus inspection functionalities. However, if a threat actor gains local administrator privileges or above, these exclusions can be exploited to halt real-time, scheduled, and manual scanning functions. This means that targeted directories, where malware could be downloaded, unpacked, and executed, may go entirely unnoticed by MDAV.

Among the different types of exclusions, path and extension exclusions present the highest risk during an intrusion. For instance, if an attacker sets an exclusion for a temporary directory or user profile location, they can utilize these spaces to store and run malicious payloads without attracting the scrutiny of antivirus tools. Similarly, extensions excluded from scanning can create significant blind spots in security, allowing harmful binaries, scripts, or even renamed payloads to infiltrate systems without detection.

Microsoft allows such exclusions to be configured through multiple platforms, including Intune, Mobile Device Management (MDM), Group Policy, PowerShell, or Windows Management Instrumentation (WMI). This array of configuration methods not only broadens the avenues through which administrators can manage MDAV, but it also provides attackers with various interfaces to manipulate after gaining elevated privileges.

When these Defender exclusions are established, associated settings are documented within the Windows Registry. This registry activity becomes particularly crucial for forensic detection, as it provides vital insights into changes made—regardless of the original configuration approach used. The policy value HideExclusionsFromLocalAdmins, located at HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\HideExclusionsFromLocalAdmins, becomes a key focal point in this context. When activated, it does not eliminate existing exclusions but simply prevents them from being displayed in ordinary local administrative queries, including standard commands like Get-MpPreference, frustrating efforts to detect unauthorized configurations.

Huntress has observed that this limitation extends even to SYSTEM-level PowerShell queries, which could potentially undermine security measures or scripts reliant purely on the Defender command-line interface for auditing exclusions. This methodology of concealment is particularly appealing to attackers, as it is far less conspicuous than simply disabling Microsoft Defender altogether—a move that would likely raise alarms, trigger security alerts, or invite immediate scrutiny from analysts.

Furthermore, the operational viability of exclusions makes this tactic even more attractive for attackers, especially on servers, developer endpoints, or systems that run business applications demanding legitimate antivirus exceptions. Historically, similar methods have been employed in real-world cyber campaigns. For instance, GootKit malware added MDAV path exclusions using WMI, while the notorious WhisperGate malware leveraged PowerShell for establishing a path exclusion for the root drive (C:\). Such actions align with MITRE ATT&CK technique T1562.001, which encompasses adversaries modifying security controls to elude detection.

In the face of these threats, cybersecurity professionals are advised not to depend solely on Get-MpPreference or the Windows Security interface for validating the configuration of Microsoft Defender. Instead, incident responders are encouraged to collect and retain alerts concerning registry modifications associated with both Defender’s exclusion keys and the HideExclusionsFromLocalAdmins setting. Specifically, attention should be paid to the following registry locations:

  • HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions
  • HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions

Any changes to or use of the HideExclusionsFromLocalAdmins setting should be thoroughly investigated, especially if they coincide with suspicious activity involving PowerShell, WMI, Group Policy alterations, or unusual credential-access attempts.

Huntress emphasizes the importance of registry-level telemetry, as every exclusion ultimately leads to a registry change that can be systematically monitored. Organizations ought to minimize local administrator privileges, enforce centralized management of Defender policies, and rigorously scrutinize whether local administrators are permitted to introduce their own exclusions that could interact with managed configurations.

Setting up a benchmark of approved exclusions and flagging broad entries—such as entire drive paths, temporary directories, user-writable folders, and unconventional IP addresses—is essential in maintaining a robust security posture. Hidden exclusions should be viewed with suspicion and treated as investigative triggers rather than standard operational protocols.

The overarching lesson is simple yet profound: the status of antivirus alone does not guarantee endpoint protection. Even with Microsoft Defender enabled and seemingly operational, attackers can quietly establish unmonitored areas for malware execution, leveraging the very exclusions intended for legitimate administrative purposes. This necessitates a comprehensive approach to endpoint security—one that underscores vigilance and proactive monitoring to combat this emerging exploitation tactic effectively.

Source link

Latest articles

Poland Investigates Breach of Second Health Software Provider

Investigation Launched After Cyberattack on Poland's Qbusoft Healthcare Software Vendor In a troubling escalation of...

Continuous Penetration Testing: Annual Pen Tests as a Compliance Checkbox Rather Than a Security Strategy

Continuous Penetration Testing: Rethinking the Efficacy of Annual Security Assessments In today's rapidly evolving cyber...

Oracle Introduces Fusion Claw AI Agentic Runtime

Oracle Unveils Fusion Claw: A Breakthrough in AI-Driven Business Process Automation In a significant advancement...

More like this

Poland Investigates Breach of Second Health Software Provider

Investigation Launched After Cyberattack on Poland's Qbusoft Healthcare Software Vendor In a troubling escalation of...

Continuous Penetration Testing: Annual Pen Tests as a Compliance Checkbox Rather Than a Security Strategy

Continuous Penetration Testing: Rethinking the Efficacy of Annual Security Assessments In today's rapidly evolving cyber...