Attackers Abuse Microsoft Defender Exclusions with HideExclusionsFromLocalAdmins to Evade Antivirus Scans

Attackers Abuse Microsoft Defender Exclusions with (TL-2026-2824) is a high-severity tracked intrusion set, first published 2026-10-01. It has no confirmed attribution, affects Microsoft Microsoft Defender Antivirus, maps to 6 MITRE ATT&CK techniques (T1012, T1047, T1059.001), and is covered by 9 detection rules and 10 indicators of compromise.

Key facts for TL-2026-2824

Threat ID
TL-2026-2824
Severity
HIGH
Status
ACTIVE
Category
THREAT_INTEL
First published
2026-10-01
Last reviewed
2026-10-01
Attribution confidence
LOW
Motivation
UNKNOWN
Detection rules
9
Indicators of compromise
10

Malware and tooling in Attackers Abuse Microsoft Defender Exclusions with

Malware and tooling: GootKit, LunarWeb - S1141, WhisperGate - S0689, GootKit, Turla

Attackers with local administrator privileges pair Microsoft Defender Antivirus exclusions with the HideExclusionsFromLocalAdmins policy setting, creating hidden blind spots where malware runs unscanned and exclusions no longer appear through standard admin tooling such as Get-MpPreference. Huntress research (published 2026-09-30) documents the technique and detection approaches; no CVE is involved.

How Attackers Abuse Microsoft Defender Exclusions with works

Microsoft Defender Antivirus (MDAV) exclusions let a user with administrator privileges or higher bypass AV scans for folders, binaries, extensions and IP addresses. Exclusion types are Process (files opened by a named process), Path (whole directories removed from real-time and scheduled scans), Extension (file types) and IpAddress (network inspection for designated IPs). Exclusions can be configured through Intune, MDM, Group Policy, PowerShell (Set-MpPreference / Add-MpPreference) and WMI (the MSFT_MpPreference class in the root/Microsoft/Windows/Defender namespace, e.g. via Invoke-CimMethod). They can also be written directly to the registry, for example with reg add under HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths.

The HideExclusionsFromLocalAdmins policy value (HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\HideExclusionsFromLocalAdmins, REG_DWORD = 1) is a legitimate hardening control meant to stop local attackers from discovering which locations are excluded. Per the sources, when enabled it prevents exclusions from appearing through ordinary local administrative queries including Get-MpPreference, and can affect SYSTEM-level PowerShell queries. NVISO's analysis notes it also hides exclusions in Registry Editor and Windows Security, and that it does not prevent an admin from creating new exclusions; it only obscures existing ones. An attacker with local admin rights can therefore add an exclusion for a payload staging path and also set the hide flag, so defenders and responders reviewing a host with ordinary tooling do not see the blind spot. Huntress notes the exclusions can still be read by querying the registry directly (HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions and HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions), which bypasses the restriction that blocks PowerShell queries for both administrators and SYSTEM.

Exclusion tampering has precedent: Huntress cites GootKit (2019), which created a Defender path exclusion via the MSFT_MpPreference WMI class, and WhisperGate (2022), which used PowerShell Set-MpPreference to exclude the C:\ drive; it also references Muddled Libra (2024) as using similar techniques. MITRE ATT&CK catalogs the generic behavior as T1562.001 (Impair Defenses: Disable or Modify Tools) and the abuse of pre-existing or well-known exclusions as T1564.012 (Hide Artifacts: File/Path Exclusions), where Turla deployed LunarWeb installer files into directories excluded from scanning. The GBHackers report (2026-10-01) states real-world use in campaigns but names no specific current actor, victims, CVE, CVSS or network/file IOCs; severity is analyst-assigned.

Defender guidance from the sources: Tamper Protection does not prevent exclusion creation; DisableLocalAdminMerge (set to 1) makes Intune/policy settings take precedence over local-admin settings, though NVISO observed locally added PowerShell exclusions persisting until a restart or policy reapplication. Detection should monitor registry-level changes to the exclusion keys and to HideExclusionsFromLocalAdmins (works regardless of whether PowerShell, WMI, GPO or manual methods were used), baseline approved exclusions, and flag broad entries such as root-drive paths, temp directories, user-writable folders, Downloads, wildcard extensions and unexpected IP exclusions, correlating with PowerShell, WMI, Group Policy, credential-access or payload-staging activity.

MITRE ATT&CK techniques used in TL-2026-2824

Discovery

T1012 Query Registry

Execution

T1047 Windows Management Instrumentation; T1059.001 Command and Scripting Interpreter: PowerShell

defense-impairment

T1112 Modify Registry; T1685 Disable or Modify Tools

Defense Evasion

T1564.012 Hide Artifacts: File/Path Exclusions

Affected products and versions in Attackers Abuse Microsoft Defender Exclusions with

  • Microsoft — Microsoft Defender Antivirus
    Vulnerable versions: Configurations where attackers hold local administrator privileges; exclusions manageable via Intune, MDM, Group Policy, PowerShell or WMI

Remediation for Attackers Abuse Microsoft Defender Exclusions with

Immediate actions

  • Query exclusions directly from the registry (HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions and HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions) instead of relying on Get-MpPreference
  • Audit hosts for HideExclusionsFromLocalAdmins set outside of approved Intune/GPO policy
  • Review and remove broad exclusions: root-drive paths, Temp, Downloads, user-writable folders, wildcard extensions, unexpected IP exclusions

Workarounds

  • Set DisableLocalAdminMerge = 1 so centrally managed (Intune/GPO) settings take precedence over local admin settings
  • Note that Tamper Protection does not block exclusion creation

Longer-term hardening

  • Baseline approved exclusions and alert on registry changes to the Defender Exclusions keys and HideExclusionsFromLocalAdmins
  • Correlate exclusion changes with PowerShell, WMI, Group Policy, credential-access and payload-staging activity
  • Restrict local administrator rights to limit who can alter Defender configuration

Timeline of Attackers Abuse Microsoft Defender Exclusions with

  • GootKit creates a Microsoft Defender path exclusion via the MSFT_MpPreference WMI class (year only per Huntress; day/month not stated)
  • WhisperGate uses PowerShell Set-MpPreference to add a Defender path exclusion for the C:\ drive (year only per Huntress; day/month not stated)
  • SentinelOne researcher Antonio Cocomazzi publicly discloses that Defender exclusions can be read by local users from the registry (month approximate per BleepingComputer: January 2022)
  • NVISO publishes analysis concluding admins cannot be blocked from adding exclusions; documents DisableLocalAdminMerge and HideExclusionsFromLocalAdmins behavior and Advanced Hunting detection on DeviceRegistryEvents
  • Muddled Libra referenced by Huntress as employing similar exclusion-abuse techniques (year only per source)
  • Huntress (author Jonathan Johnson) publishes 'You Can Run, but You Can't Hide: Defender Exclusions' covering HideExclusionsFromLocalAdmins abuse, registry querying and detections
  • GBHackers reports attackers hiding Defender exclusions from admins to evade AV scans, citing Huntress research and MITRE T1562.001

Sources cited for Attackers Abuse Microsoft Defender Exclusions with

More in threat intel

Detection coverage for TL-2026-2824

As of 2026-10-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2824 across Splunk SPL, Microsoft KQL and Sigma, covering 10 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats