Microsoft Defender Antivirus Exclusion Abuse: Attackers Set and Hide Exclusions (HideExclusionsFromLocalAdmins) to Evade MDAV

Microsoft Defender Antivirus Exclusion Abuse (TL-2026-2828) is a medium-severity tracked intrusion set, first published 2026-10-01. It has no confirmed attribution, affects Microsoft Microsoft Defender Antivirus (Windows), maps to 7 MITRE ATT&CK techniques (T1047, T1059.001, T1112), and is covered by 9 detection rules and 9 indicators of compromise.

Key facts for TL-2026-2828

Threat ID
TL-2026-2828
Severity
MEDIUM
Status
MONITORING
Category
THREAT_INTEL
First published
2026-10-01
Last reviewed
2026-10-01
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
all
Target regions
Global
Detection rules
9
Indicators of compromise
9

Malware and tooling in Microsoft Defender Antivirus Exclusion Abuse

Malware and tooling: GootKit, WhisperGate - S0689, GootKit

Huntress documents how attackers holding admin/SYSTEM rights add Microsoft Defender Antivirus exclusions via PowerShell, WMI, Group Policy or registry so malware escapes scanning, and set the HideExclusionsFromLocalAdmins registry value to conceal those exclusions from local administrators. The technique has prior in-the-wild use by GootKit (2019), WhisperGate (2022) and Muddled Libra (2024).

How Microsoft Defender Antivirus Exclusion Abuse works

Microsoft Defender Antivirus (MDAV) supports four exclusion types: Process (no real-time scanning of files opened by a given process), Path (entire paths skipped by real-time and scheduled scans), Extension (file extensions skipped) and IpAddress (network packet inspection skipped for a given IP). Any actor with local administrator or SYSTEM privileges can abuse these to create a blind spot for payloads, tooling and staging directories.

Huntress (Jonathan Johnson, 2026-09-30) describes four ways exclusions are written. (1) PowerShell: Set-MpPreference / Add-MpPreference -ExclusionPath (e.g. C:\Temp), which route through the MSFT_MpPreference WMI class, COM/RPC and the MsMpEng.exe service. (2) WMI directly: Invoke-CimMethod against namespace root/Microsoft/Windows/Defender, class MSFT_MpPreference, method Add, with an ExclusionPath argument (plus ThreatIDDefaultAction arguments and Force=$true). (3) Group Policy: Computer Configuration > Administrative Templates > Windows Components > Microsoft Defender Antivirus > Exclusions, applied by the gpsvc svchost and stored under HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions. (4) Direct registry modification of the policy key (e.g. reg add of a value under ...\Exclusions\Paths), which requires a reboot or policy refresh to take effect. Direct writes to the MDAV-owned key HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions are protected by MDAV and not feasible from userland.

To conceal the exclusions, attackers can set the HKLM\SOFTWARE\Policies\Microsoft\Windows Defender HideExclusionsFromLocalAdmins value (REG_DWORD = 1). This does not remove or block exclusions; it stops local administrators from enumerating them through Get-MpPreference, the Windows Security app and the registry editor view, so a responder or admin running standard queries sees an empty list. Per NVISO (2022), Tamper Protection and DisableLocalAdminMerge do not stop an admin from adding exclusions, so detection (not prevention) is the control.

Historical use cited by Huntress: GootKit (2019) used a UAC bypass and WMI/WMIC to add a path exclusion for its own executable; WhisperGate (2022) used PowerShell Set-MpPreference -ExclusionPath 'C:\' (and AdvancedRun.exe to stop the Defender service) before its wiper stages; Muddled Libra (2024) is cited by Unit 42 as using Defender exclusions. The source contains no CVE, no CVSS, no network IOCs and no named victims, so severity is analyst-assigned.

MITRE ATT&CK techniques used in TL-2026-2828

Execution

T1047 Windows Management Instrumentation; T1059.001 PowerShell

defense-impairment

T1112 Modify Registry

Privilege Escalation

T1484.001 Group Policy Modification; T1548.002 Bypass User Account Control

Stealth

T1564.012 File/Path Exclusions

Defense Impairment

T1685 Disable or Modify Tools

Affected products and versions in Microsoft Defender Antivirus Exclusion Abuse

  • Microsoft — Microsoft Defender Antivirus (Windows)
    Vulnerable versions: Configuration abuse, not a software flaw: any system where an attacker holds local admin/SYSTEM

Remediation for Microsoft Defender Antivirus Exclusion Abuse

Immediate actions

  • Audit current exclusions by reading the registry directly (HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions and HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions) rather than relying on Get-MpPreference, which HideExclusionsFromLocalAdmins can blank out
  • Check HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\HideExclusionsFromLocalAdmins on every endpoint and investigate unmanaged values of 1
  • Remove unauthorized exclusions, especially C:\, Temp, Downloads and known-bad binaries, and rescan the covered paths

Workarounds

  • Tamper Protection and DisableLocalAdminMerge do not prevent admins from adding exclusions; rely on detection and privilege reduction instead

Longer-term hardening

  • Alert on registry writes to the MDAV and policy Exclusions keys and on the HideExclusionsFromLocalAdmins value regardless of the method used (PowerShell, WMI, GPO, reg.exe)
  • Alert on Set-MpPreference / Add-MpPreference -Exclusion* and Invoke-CimMethod against MSFT_MpPreference outside of approved change windows
  • Allow-list legitimate, centrally managed exclusions to keep false positives low
  • Restrict local administrator and SYSTEM-equivalent access to limit who can alter Defender configuration

Timeline of Microsoft Defender Antivirus Exclusion Abuse

  • GootKit banking trojan sample reported using a UAC bypass and WMI/WMIC to add a Windows Defender path exclusion for its own executable (BleepingComputer, via CERT.at daily summary)
  • WhisperGate wiper first observed targeting Ukrainian organizations; sets a Defender exclusion for C:\ via PowerShell Set-MpPreference and uses AdvancedRun.exe to stop the Defender service
  • NVISO publishes research showing Tamper Protection and DisableLocalAdminMerge do not block local exclusion changes; HideExclusionsFromLocalAdmins only hides them
  • Unit 42 reporting on Muddled Libra (2024) cited by Huntress as prior in-the-wild use of Defender exclusions
  • Huntress publishes 'You Can Run, but You Can't Hide: Defender Exclusions' detailing PowerShell, WMI, GPO and registry exclusion methods and the HideExclusionsFromLocalAdmins concealment value
  • Threadlinqs begins tracking Defender exclusion abuse and HideExclusionsFromLocalAdmins as a defense-evasion technique with no associated CVE

Sources cited for Microsoft Defender Antivirus Exclusion Abuse

More in threat intel

Detection coverage for TL-2026-2828

As of 2026-10-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2828 across Splunk SPL, Microsoft KQL and Sigma, covering 9 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats