#WindowsDefender

2025-05-30

#WindowsDefender team: Please test and ensure that new Ollama installers run as expected on Windows, even with ASR rules enabled.

#Ollama team: please test and ensure your installers work on Windows with Windows Defender ASR rules enabled.

K? Thanks!

Kevin Karhan :verified:kkarhan@infosec.space
2025-05-29

@mrgrumpymonkey depends...

Next logical step is some #PowerShell script that downloads a #Linux distro image, repartition the system drive, add some unallocated space at the end, put a #CloudInit config in it and then do an #UnattendedInstall of said system with bcd by calling up #bcdedit to #chainload said partition.

  • I jist have neither the time nor spoons to do that shit myself, but in theory a #NetInstaller image of ~ 100MB should suffice...
Kevin Karhan :verified:kkarhan@infosec.space
2025-05-22

@GossiTheDog @signalapp it merely prevents #Screenshots by claiming it's #DRM'd content.

The correct solution for #Signal would be to alert all their users and specifically block #Windows in general or at least #Windows11 simply because it is a #Govware and empirically cannot be made private or secure.

But that would require them to actually give a shit, which thed don't, cuz otherwise they would've stopped demanding #PII like a #PhoneNumber and moved out of juristiction of #CloudAct.

  • I mean, what's gonna prevent the #Trump-Regime from threatening @Mer__edith et. al. with lifetime in jail for not kicking the #ICC (or anyone else he and his fans dislike) from #Signal's infrastructure?

Since they are highly centralized.they certainly are capable to comply with "#Sanctions" (or whatever bs he'll claim!)...

WinFuture.deWinFuture
2025-05-19

Ein Sicherheitsforscher enthüllt mit "Defendnot" eine kritische Schwachstelle im Windows Security Center. Das Tool täuscht ein falsches Antivirenprogramm vor und deaktiviert so den . winfuture.de/news,151018.html?

Torsten :verified: :verified:tor@norden.social
2025-04-18

I'd like to change a password of a local account on Windows 10.

Can #chntpw still do the job in 2025 (with #SAM)?

I have read that Windows Defender blocks some changes like #sethc, #utilman and so on ...

#Windows #Linux #Windows10 #WindowsDefender #MicrosoftDefender #infosec #fedihelp

kriware :verified:kriware@infosec.exchange
2025-04-13

Bypassing Windows Defender Antivirus in 2025

This article explores methods to bypass Windows Defender in 2025, focusing on direct syscalls and XOR encryption for shellcode execution.

hackmosphere.fr/bypass-windows

#WindowsDefender #AntivirusEvasion

2025-03-26

@SecurityWriter Individual hobbyists who develop games and other programs for Windows often ask the user to bypass SmartScreen because the dev can't afford a commercial code signing certificate. Is that also just like "disable their security software"?

#WindowsDefender #SmartScreen #CodeSigning #CARacket

Steve Dustcircle 🌹dustcircle
2025-03-18
teletechdigital128teletechdigital
2025-03-18

If you're experiencing issues with Microsoft Azure or need assistance with your cloud services, contact the Microsoft Azure customer service team for expert support. They’ll help you solve any challenges you face with Azure’s platform. For fast assistance, visit: teletechdigital.com/microsoft-

, , , , , , , , , , ,

WinFuture.deWinFuture
2025-03-14

Windows Defender stuft beliebte PC-Wartungstools als Bedrohung ein. Der Grund: Der veraltete WinRing0-Treiber. Betroffen sind u.a. Fan Control und MSI Afterburner. winfuture.de/news,149592.html?

2025-02-20

#WindowsDefender active, application cold start time: 60 Seconds
Windows Defender active, application warm start time: 8 Seconds

Windows Defender disabled (Tamper, Realtime, "Reputation" protections)
Cold: 13 Seconds
Warm: 8 Seconds

You idiots, #Microsoft.

#Windows #SnakeOil

2025-02-03

#WindowsDefender, screws you every day another way.

#Microsoft #Windows

2024-12-16

I just replied to a blog comment, and I thought that I post my reply here as well:

I think that I have good reasons to be “against Avast,” having published seven articles on them so far. The security issues alone are bad enough. But Avast abused their position to collect and sell users’ browsing profiles. After they were caught they claimed the data to be anonymized, they claimed to only sell aggregated data – and they continue lying to this day, despite there being conclusive evidence to the contrary. While the company has been bought, it’s still the same people in charge. This sort of undermines any trust in them for anything related to security.

As the security of antivirus software goes, I’m not very fond of any as the articles in the “antivirus” category of my blog show. With Kaspersky it wasn’t only the security issues but also how they handled them, pushing out half-hearted fixes only for these to be circumvented shortly afterwards. McAfee and BullGuard had massive security issues stemming from being careless about security and not following best practices.

I’ve found a critical security issue in Bitdefender’s solution as well, but with them I at least had the impression that they were trying. Unfortunately, that’s currently the bar in the antivirus industry – at least trying to make their product secure.

Security-wise, one good thing about Windows Defender is that it only needs to do one job. It doesn’t need all the extra functionality as a selling argument. It doesn’t need to be a banking browser, it doesn’t need to be a phishing protection, it only needs to be an antivirus solution. It can keep a very small attack surface compared to all those antivirus suites, and so it does (yes, I checked).

#antivirus #security #avast #McAfee #BullGuard #Bitdefender #WindowsDefender

WinFuture.deWinFuture
2024-12-16

Microsoft behebt kritische Schwachstelle in Windows Defender. Die Indexierungsfunktion ermöglichte potenziell unbefugten Zugriff auf sensible Daten. Nutzer müssen nicht aktiv werden. winfuture.de/news,147556.html?

2024-11-16

The following is currently being flagged by Windows Defender on Windows 10:
rustc 1.82.0 (f6e511eec 2024-10-15)

cargo install rage
...
error: failed to run custom build command for `libm v0.2.11`
...
Caused by:
Operation did not complete successfully because the file contains a virus or potentially unwanted software. (os error 225)

Is this a known false positive?

#rust #cargo #antivirus #windowsdefender #libm

DeepSec Conference ☑deepsec@social.tchncs.de
2024-10-17

DeepSec 2024 Talk: Windows Defender Internals – Baptiste David

Microsoft Defender Antivirus (aka Windows Defender) is an antivirus deployed worldwide and used by default on every Windows out-of-the-box. We all use it but who knows exactly how it really works? What is inside this software trust

blog.deepsec.net/deepsec-2024-

#Conference #DeepSec2024 #MicrosoftDefenderAntivirus #MsMpEngex #SmartAppControl #Talk #WindowsDefender

2024-10-11

Amazing. My work computer's Windows Defender is creating a constant ~40% CPU load because of CLion. CLion is smart enough to recommend adding an exception, but I'm not allowed to 🤡

Gosh, why is corporate IT such a joke?

#Windows #CLion #Defender #WindowsDefender #Microsoft #JetBrains #IT #InfoSec

lfa :emacs: :tux: :freebsd:lfa@hostux.social
2024-08-22

🇬🇧 I've been saying that #windows is a #virus since the 90s, and people is starting to get it now.

In fact some fables and legends tell that #WindowsDefender was created with the sole purpose of having an antivirus software that did not detect Windows as a threat 😜

arstechnica.com/security/2024/

lfa :emacs: :tux: :freebsd:lfa@hostux.social
2024-08-22

🇪🇸 Yo llevo desde los 90 diciendo que #windows es un #virus y la gente empieza a entenderlo ahora

De hecho cuenta la leyenda que #WindowsDefender se creó con el único propósito de tener un software antivirus que no detectara a Windows como una amenaza 😜

arstechnica.com/security/2024/

Chema Alonso :verified:chemaalonso@ioc.exchange
2024-08-18

El lado del mal - Evil Signature Injection: Borrado remoto de bases de datos, buzones de correos y ficheros de log con Evil Signatures y tu EDR elladodelmal.com/2024/08/evil- #EvilSignature #EDR #WindowsDefender #hacking #pentest #hardening

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst