Microsoft Defender Antivirus Exclusion Abuse: Attackers Set and Hide Exclusions (HideExclusionsFromLocalAdmins) to Evade MDAV
Microsoft Defender Antivirus Exclusion Abuse (TL-2026-2828) is a medium-severity tracked intrusion set, first published 2026-10-01. It has no confirmed attribution, affects Microsoft Microsoft Defender Antivirus (Windows), maps to 7 MITRE ATT&CK techniques (T1047, T1059.001, T1112), and is covered by 9 detection rules and 9 indicators of compromise.
Key facts for TL-2026-2828
- Threat ID
- TL-2026-2828
- Severity
- MEDIUM
- Status
- MONITORING
- Category
- THREAT_INTEL
- First published
- 2026-10-01
- Last reviewed
- 2026-10-01
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- all
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 9
Malware and tooling in Microsoft Defender Antivirus Exclusion Abuse
Malware and tooling: GootKit, WhisperGate - S0689, GootKit
Huntress documents how attackers holding admin/SYSTEM rights add Microsoft Defender Antivirus exclusions via PowerShell, WMI, Group Policy or registry so malware escapes scanning, and set the HideExclusionsFromLocalAdmins registry value to conceal those exclusions from local administrators. The technique has prior in-the-wild use by GootKit (2019), WhisperGate (2022) and Muddled Libra (2024).
How Microsoft Defender Antivirus Exclusion Abuse works
Microsoft Defender Antivirus (MDAV) supports four exclusion types: Process (no real-time scanning of files opened by a given process), Path (entire paths skipped by real-time and scheduled scans), Extension (file extensions skipped) and IpAddress (network packet inspection skipped for a given IP). Any actor with local administrator or SYSTEM privileges can abuse these to create a blind spot for payloads, tooling and staging directories.
Huntress (Jonathan Johnson, 2026-09-30) describes four ways exclusions are written. (1) PowerShell: Set-MpPreference / Add-MpPreference -ExclusionPath (e.g. C:\Temp), which route through the MSFT_MpPreference WMI class, COM/RPC and the MsMpEng.exe service. (2) WMI directly: Invoke-CimMethod against namespace root/Microsoft/Windows/Defender, class MSFT_MpPreference, method Add, with an ExclusionPath argument (plus ThreatIDDefaultAction arguments and Force=$true). (3) Group Policy: Computer Configuration > Administrative Templates > Windows Components > Microsoft Defender Antivirus > Exclusions, applied by the gpsvc svchost and stored under HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions. (4) Direct registry modification of the policy key (e.g. reg add of a value under ...\Exclusions\Paths), which requires a reboot or policy refresh to take effect. Direct writes to the MDAV-owned key HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions are protected by MDAV and not feasible from userland.
To conceal the exclusions, attackers can set the HKLM\SOFTWARE\Policies\Microsoft\Windows Defender HideExclusionsFromLocalAdmins value (REG_DWORD = 1). This does not remove or block exclusions; it stops local administrators from enumerating them through Get-MpPreference, the Windows Security app and the registry editor view, so a responder or admin running standard queries sees an empty list. Per NVISO (2022), Tamper Protection and DisableLocalAdminMerge do not stop an admin from adding exclusions, so detection (not prevention) is the control.
Historical use cited by Huntress: GootKit (2019) used a UAC bypass and WMI/WMIC to add a path exclusion for its own executable; WhisperGate (2022) used PowerShell Set-MpPreference -ExclusionPath 'C:\' (and AdvancedRun.exe to stop the Defender service) before its wiper stages; Muddled Libra (2024) is cited by Unit 42 as using Defender exclusions. The source contains no CVE, no CVSS, no network IOCs and no named victims, so severity is analyst-assigned.
MITRE ATT&CK techniques used in TL-2026-2828
Execution
T1047 Windows Management Instrumentation; T1059.001 PowerShell
defense-impairment
Privilege Escalation
T1484.001 Group Policy Modification; T1548.002 Bypass User Account Control
Stealth
T1564.012 File/Path Exclusions
Defense Impairment
Affected products and versions in Microsoft Defender Antivirus Exclusion Abuse
- Microsoft — Microsoft Defender Antivirus (Windows)
Vulnerable versions: Configuration abuse, not a software flaw: any system where an attacker holds local admin/SYSTEM
Remediation for Microsoft Defender Antivirus Exclusion Abuse
Immediate actions
- Audit current exclusions by reading the registry directly (HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions and HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions) rather than relying on Get-MpPreference, which HideExclusionsFromLocalAdmins can blank out
- Check HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\HideExclusionsFromLocalAdmins on every endpoint and investigate unmanaged values of 1
- Remove unauthorized exclusions, especially C:\, Temp, Downloads and known-bad binaries, and rescan the covered paths
Workarounds
- Tamper Protection and DisableLocalAdminMerge do not prevent admins from adding exclusions; rely on detection and privilege reduction instead
Longer-term hardening
- Alert on registry writes to the MDAV and policy Exclusions keys and on the HideExclusionsFromLocalAdmins value regardless of the method used (PowerShell, WMI, GPO, reg.exe)
- Alert on Set-MpPreference / Add-MpPreference -Exclusion* and Invoke-CimMethod against MSFT_MpPreference outside of approved change windows
- Allow-list legitimate, centrally managed exclusions to keep false positives low
- Restrict local administrator and SYSTEM-equivalent access to limit who can alter Defender configuration
Timeline of Microsoft Defender Antivirus Exclusion Abuse
- GootKit banking trojan sample reported using a UAC bypass and WMI/WMIC to add a Windows Defender path exclusion for its own executable (BleepingComputer, via CERT.at daily summary)
- WhisperGate wiper first observed targeting Ukrainian organizations; sets a Defender exclusion for C:\ via PowerShell Set-MpPreference and uses AdvancedRun.exe to stop the Defender service
- NVISO publishes research showing Tamper Protection and DisableLocalAdminMerge do not block local exclusion changes; HideExclusionsFromLocalAdmins only hides them
- Unit 42 reporting on Muddled Libra (2024) cited by Huntress as prior in-the-wild use of Defender exclusions
- Huntress publishes 'You Can Run, but You Can't Hide: Defender Exclusions' detailing PowerShell, WMI, GPO and registry exclusion methods and the HideExclusionsFromLocalAdmins concealment value
- Threadlinqs begins tracking Defender exclusion abuse and HideExclusionsFromLocalAdmins as a defense-evasion technique with no associated CVE
Sources cited for Microsoft Defender Antivirus Exclusion Abuse
- You Can Run, but You Can't Hide: Defender Exclusions (Huntress)
- Can we block the addition of local Microsoft Defender Antivirus exclusions? (NVISO)
- Configure exclusions in Microsoft Defender Antivirus (Microsoft Learn)
- Ukraine Cyber Conflict: WhisperGate (Unit 42)
- Threat Group Assessment: Muddled Libra (Unit 42)
- GootKit Malware Bypasses Windows Defender by Setting Path Exclusions
- MITRE ATT&CK S0689: WhisperGate
- Splunk Research: PowerShell Windows Defender Exclusion Commands
- Sigma: Windows Defender Exclusion List Modified (registry)
More in threat intel
- Attackers Abuse Microsoft Defender Exclusions with HideExclusionsFromLocalAdmins to Evade Antivirus Scans
- Insiders for Hire: Underground Market for Employee Access Expands Beyond Privileged IT Roles
- Agentic AI used for post-exploitation in breach of the Dutch Institute for Vulnerability Disclosure (DIVD)
- Hacker-for-Hire Economy: Cyber Mercenaries Offer Account Compromise, Surveillance, Doxxing and DDoS as a Service
- ASEC August 2026 Financial Sector Threat Landscape: LockBit 5.0 Ransomware Activity, Phishing Dominance, and Multiple Unverified Data-Breach Claims
Detection coverage for TL-2026-2828
As of 2026-10-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2828 across Splunk SPL, Microsoft KQL and Sigma, covering 9 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.