Skip to main content
Skip to main content
Microsoft Security Intelligence
12 entries found.
Updated on Dec 13, 2019

Microsoft researchers regularly see popular, publicly-available tools being leveraged by attackers. Defender Control, a publicly available software program allows users to one-click disable/enable Microsoft Defender Antivirus.

Threat actors use malware and publicly available software to tamper with security solutions. To run these tampering tools successfully against a system with Tamper Protection enabled, an attacker must have access to sufficient privileges to run the program as Trusted Installer, NT Authority, or System. Beginning in 2022, Microsoft introduced a functionality in Defender Antivirus that further limits the effectiveness of malicious antivirus tampering tools by not allowing the use of a trusted installer for service change or registry modification.

Alert level: high
Updated on Oct 02, 2020
Alert level: high
Updated on Oct 18, 2021
Alert level: high
Updated on Oct 18, 2021
Alert level: high
Updated on Nov 05, 2021
Alert level: high
Updated on May 17, 2022
Alert level: high
Updated on Sep 15, 2023
Alert level: high
Updated on Mar 04, 2022
Alert level: high
Updated on May 12, 2020
Alert level: high
Updated on Jun 19, 2021
Alert level: high
Updated on May 22, 2024
Alert level: high
Updated on Apr 18, 2021
Alert level: high