Attackers Abuse Microsoft Defender Exclusions with HideExclusionsFromLocalAdmins to Evade Antivirus Scans
Attackers Abuse Microsoft Defender Exclusions with (TL-2026-2824) is a high-severity tracked intrusion set, first published 2026-10-01. It has no confirmed attribution, affects Microsoft Microsoft Defender Antivirus, maps to 6 MITRE ATT&CK techniques (T1012, T1047, T1059.001), and is covered by 9 detection rules and 10 indicators of compromise.
Key facts for TL-2026-2824
- Threat ID
- TL-2026-2824
- Severity
- HIGH
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- 2026-10-01
- Last reviewed
- 2026-10-01
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Detection rules
- 9
- Indicators of compromise
- 10
Malware and tooling in Attackers Abuse Microsoft Defender Exclusions with
Malware and tooling: GootKit, LunarWeb - S1141, WhisperGate - S0689, GootKit, Turla
Attackers with local administrator privileges pair Microsoft Defender Antivirus exclusions with the HideExclusionsFromLocalAdmins policy setting, creating hidden blind spots where malware runs unscanned and exclusions no longer appear through standard admin tooling such as Get-MpPreference. Huntress research (published 2026-09-30) documents the technique and detection approaches; no CVE is involved.
How Attackers Abuse Microsoft Defender Exclusions with works
Microsoft Defender Antivirus (MDAV) exclusions let a user with administrator privileges or higher bypass AV scans for folders, binaries, extensions and IP addresses. Exclusion types are Process (files opened by a named process), Path (whole directories removed from real-time and scheduled scans), Extension (file types) and IpAddress (network inspection for designated IPs). Exclusions can be configured through Intune, MDM, Group Policy, PowerShell (Set-MpPreference / Add-MpPreference) and WMI (the MSFT_MpPreference class in the root/Microsoft/Windows/Defender namespace, e.g. via Invoke-CimMethod). They can also be written directly to the registry, for example with reg add under HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths.
The HideExclusionsFromLocalAdmins policy value (HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\HideExclusionsFromLocalAdmins, REG_DWORD = 1) is a legitimate hardening control meant to stop local attackers from discovering which locations are excluded. Per the sources, when enabled it prevents exclusions from appearing through ordinary local administrative queries including Get-MpPreference, and can affect SYSTEM-level PowerShell queries. NVISO's analysis notes it also hides exclusions in Registry Editor and Windows Security, and that it does not prevent an admin from creating new exclusions; it only obscures existing ones. An attacker with local admin rights can therefore add an exclusion for a payload staging path and also set the hide flag, so defenders and responders reviewing a host with ordinary tooling do not see the blind spot. Huntress notes the exclusions can still be read by querying the registry directly (HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions and HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions), which bypasses the restriction that blocks PowerShell queries for both administrators and SYSTEM.
Exclusion tampering has precedent: Huntress cites GootKit (2019), which created a Defender path exclusion via the MSFT_MpPreference WMI class, and WhisperGate (2022), which used PowerShell Set-MpPreference to exclude the C:\ drive; it also references Muddled Libra (2024) as using similar techniques. MITRE ATT&CK catalogs the generic behavior as T1562.001 (Impair Defenses: Disable or Modify Tools) and the abuse of pre-existing or well-known exclusions as T1564.012 (Hide Artifacts: File/Path Exclusions), where Turla deployed LunarWeb installer files into directories excluded from scanning. The GBHackers report (2026-10-01) states real-world use in campaigns but names no specific current actor, victims, CVE, CVSS or network/file IOCs; severity is analyst-assigned.
Defender guidance from the sources: Tamper Protection does not prevent exclusion creation; DisableLocalAdminMerge (set to 1) makes Intune/policy settings take precedence over local-admin settings, though NVISO observed locally added PowerShell exclusions persisting until a restart or policy reapplication. Detection should monitor registry-level changes to the exclusion keys and to HideExclusionsFromLocalAdmins (works regardless of whether PowerShell, WMI, GPO or manual methods were used), baseline approved exclusions, and flag broad entries such as root-drive paths, temp directories, user-writable folders, Downloads, wildcard extensions and unexpected IP exclusions, correlating with PowerShell, WMI, Group Policy, credential-access or payload-staging activity.
MITRE ATT&CK techniques used in TL-2026-2824
Discovery
Execution
T1047 Windows Management Instrumentation; T1059.001 Command and Scripting Interpreter: PowerShell
defense-impairment
T1112 Modify Registry; T1685 Disable or Modify Tools
Defense Evasion
Affected products and versions in Attackers Abuse Microsoft Defender Exclusions with
- Microsoft — Microsoft Defender Antivirus
Vulnerable versions: Configurations where attackers hold local administrator privileges; exclusions manageable via Intune, MDM, Group Policy, PowerShell or WMI
Remediation for Attackers Abuse Microsoft Defender Exclusions with
Immediate actions
- Query exclusions directly from the registry (HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions and HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions) instead of relying on Get-MpPreference
- Audit hosts for HideExclusionsFromLocalAdmins set outside of approved Intune/GPO policy
- Review and remove broad exclusions: root-drive paths, Temp, Downloads, user-writable folders, wildcard extensions, unexpected IP exclusions
Workarounds
- Set DisableLocalAdminMerge = 1 so centrally managed (Intune/GPO) settings take precedence over local admin settings
- Note that Tamper Protection does not block exclusion creation
Longer-term hardening
- Baseline approved exclusions and alert on registry changes to the Defender Exclusions keys and HideExclusionsFromLocalAdmins
- Correlate exclusion changes with PowerShell, WMI, Group Policy, credential-access and payload-staging activity
- Restrict local administrator rights to limit who can alter Defender configuration
Timeline of Attackers Abuse Microsoft Defender Exclusions with
- GootKit creates a Microsoft Defender path exclusion via the MSFT_MpPreference WMI class (year only per Huntress; day/month not stated)
- WhisperGate uses PowerShell Set-MpPreference to add a Defender path exclusion for the C:\ drive (year only per Huntress; day/month not stated)
- SentinelOne researcher Antonio Cocomazzi publicly discloses that Defender exclusions can be read by local users from the registry (month approximate per BleepingComputer: January 2022)
- NVISO publishes analysis concluding admins cannot be blocked from adding exclusions; documents DisableLocalAdminMerge and HideExclusionsFromLocalAdmins behavior and Advanced Hunting detection on DeviceRegistryEvents
- Muddled Libra referenced by Huntress as employing similar exclusion-abuse techniques (year only per source)
- Huntress (author Jonathan Johnson) publishes 'You Can Run, but You Can't Hide: Defender Exclusions' covering HideExclusionsFromLocalAdmins abuse, registry querying and detections
- GBHackers reports attackers hiding Defender exclusions from admins to evade AV scans, citing Huntress research and MITRE T1562.001
Sources cited for Attackers Abuse Microsoft Defender Exclusions with
- Hackers Hide Microsoft Defender Exclusions From Admins to Evade Antivirus Scans (GBHackers)
- You Can Run, but You Can't Hide: Defender Exclusions (Huntress)
- Defence Impairment Olympics (Huntress)
- Threat Actor Defense Evasion: How Attackers Disable AV & EDR (Huntress)
- MITRE ATT&CK T1562.001 Impair Defenses: Disable or Modify Tools
- MITRE ATT&CK T1564.012 Hide Artifacts: File/Path Exclusions
- Can we block the addition of local Microsoft Defender Antivirus exclusions? (NVISO)
- Microsoft Defender weakness lets hackers bypass malware detection (BleepingComputer)
- Huntress Labs on X: Microsoft Defender Antivirus exclusions
More in threat intel
- Microsoft Defender Antivirus Exclusion Abuse: Attackers Set and Hide Exclusions (HideExclusionsFromLocalAdmins) to Evade MDAV
- Insiders for Hire: Underground Market for Employee Access Expands Beyond Privileged IT Roles
- Agentic AI used for post-exploitation in breach of the Dutch Institute for Vulnerability Disclosure (DIVD)
- Hacker-for-Hire Economy: Cyber Mercenaries Offer Account Compromise, Surveillance, Doxxing and DDoS as a Service
- ASEC August 2026 Financial Sector Threat Landscape: LockBit 5.0 Ransomware Activity, Phishing Dominance, and Multiple Unverified Data-Breach Claims
Detection coverage for TL-2026-2824
As of 2026-10-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2824 across Splunk SPL, Microsoft KQL and Sigma, covering 10 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.