Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Exploit Defender Exclusions to Bypass Antivirus

Hackers Exploit Defender Exclusions to Bypass Antivirus

Posted on October 1, 2026 By CWS

Hackers are increasingly utilizing Microsoft Defender Antivirus exclusions to bypass standard security scans, keeping malware hidden while the antivirus software remains operational. This tactic involves creating gaps around malware folders and specific file types, allowing malicious files to evade detection.

Understanding the Exploitation Technique

This approach is not a new form of malware but rather an evasion technique that demands administrative privileges. Attackers typically leverage this method after gaining significant control over a system. This method allows them to manipulate security settings without completely disabling antivirus protection.

Reports on fake desktop installers have highlighted how malicious downloads can alter exclusion settings to hide remote access malware. Huntress researchers have pointed out the growing use of this technique, which offers a stealthier alternative for attackers looking to avoid detection.

Implications for Cybersecurity

A recent report by Huntress shared with Cyber Security News connects this technique to several past malware incidents, including GootKit in 2019 and WhisperGate in 2022. While the report does not specify the number of affected victims, it underscores a recurring vulnerability in security configurations that attackers exploit to conceal their activities.

Defender allows exclusions for paths, file extensions, processes, and IP addresses. This means attackers can exclude certain directories or file types from scans, effectively hiding their malware. Techniques like PowerShell commands, Windows Management Instrumentation, and registry changes are commonly used to alter these settings.

Detection and Prevention Strategies

Detecting misuse of these settings involves scrutinizing changes and understanding why they were made. Registry monitoring is crucial, as exclusion changes are ultimately reflected there, regardless of how they were implemented. Huntress emphasizes that examining both local antivirus configurations and centrally managed policies is essential during investigations.

Despite Defender’s protective measures, attackers can alter Group Policy settings to manipulate exclusions. This requires a system reboot to activate the changes, which is an important detail for reconstructing an intrusion timeline.

Future Outlook

The evolving landscape of cyber threats necessitates heightened vigilance and adaptive security strategies. Organizations should continuously monitor security configurations and educate personnel about potential vulnerabilities. As attackers refine their tactics, cybersecurity teams must stay ahead by employing comprehensive monitoring tools and maintaining robust incident response plans.

Cyber Security News Tags:Antivirus, cyber threats, Cybersecurity, exclusion techniques, Hacking, IT security, Malware, Microsoft Defender, PowerShell, security evasion

Post navigation

Previous Post: Microsoft Activates Windows 11 Backup Setting for Businesses

Related Posts

AI Aids Hacker in Swift 72-Hour AWS Cloud Breach AI Aids Hacker in Swift 72-Hour AWS Cloud Breach Cyber Security News
Ransomware Threat via Microsoft Teams Grows Ransomware Threat via Microsoft Teams Grows Cyber Security News
Betterleaks: The Advanced Open-Source Secrets Scanner Betterleaks: The Advanced Open-Source Secrets Scanner Cyber Security News
Anthropic MCP Flaw Exposes Millions to Cyber Threats Anthropic MCP Flaw Exposes Millions to Cyber Threats Cyber Security News
Actionable Threat Intelligence for Mitigating Emerging Cyber Threats Actionable Threat Intelligence for Mitigating Emerging Cyber Threats Cyber Security News
Security Flaw in Tata’s B2B Platform Exposed User Accounts Security Flaw in Tata’s B2B Platform Exposed User Accounts Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Exploit Defender Exclusions to Bypass Antivirus
  • Microsoft Activates Windows 11 Backup Setting for Businesses
  • Mac Users Targeted by Fake Zoom Installer and CloudSyncD Backdoor
  • AI-Aided Hack Exploits Zammad Vulnerabilities
  • FTC Probes AI Firms Over Customer Safety Concerns

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Exploit Defender Exclusions to Bypass Antivirus
  • Microsoft Activates Windows 11 Backup Setting for Businesses
  • Mac Users Targeted by Fake Zoom Installer and CloudSyncD Backdoor
  • AI-Aided Hack Exploits Zammad Vulnerabilities
  • FTC Probes AI Firms Over Customer Safety Concerns

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark