4 ms·
I agree, but > Windows Defender does its job and gets out of the way WD is easily bypassed [1]. It's all smoke and mirrors - Microsoft has never cared about s
by p1peridine 5y ago
I agree, but
> Windows Defender does its job and gets out of the way
WD is easily bypassed [1]. It's all smoke and mirrors - Microsoft has never cared about security. The OS is full of wontfix exploits (this is frowned upon to talk about in the security research community, especially among the big players, wonder why...)
One would benefit in exploring the thought that WD is valuable for MS in the way that it can be used to restrict 'personal computing' - the applications you download and use, the files you download and create, all recorded and hashed in some database, all under the guise of security. DeCSS is a good example [2].
One would also benefit in exploring the thought of the possibility that MS spends significant amounts of money in paying off MS partners, researchers, news outlets etc. to convince the public that defender will keep you safe.
I repeat, Microsoft does not care about security. That said, a properly hardened Windows 10 Enterprise LTSC with telemetry removed [3], along with a third-party/router firewall is the way to go, in my opinion.
[1] https://github.com/search?o=desc&q=Windows+Defender&s=updated&type=Repositories https://github.com/search?o=desc&q=Windows+Defender&s=update...
[2] https://www.arch13.com/ms-windows-defender-decss/ https://www.arch13.com/ms-windows-defender-decss/
[3] https://www.bsi.bund.de/EN/Topics/Cyber-Security/Recommendations/SiSyPHuS_Win10/AP4/SiSyPHuS_AP4_node.html https://www.bsi.bund.de/EN/Topics/Cyber-Security/Recommendat...
- CSm1n 5y agoThe repositories shown on the first page of GitHub search are not actual exploits. They all expect to be run through an admin powershell/command line. Under normal conditions (default user and UAC on) you will get a warning before the script is able to gain administrative access. Try to run them again under a normal user and they won't be able to disable/bypass Defender. It's the same as sudo'ing an unknown script you received in an email. At that point you're begging to be pwned.
- p1peridine 5y agoSort by Best match or Most stars. Those github repos are just examples. Pro malware creators wouldn't just copy and paste some code or else it would be detected fairly easily. UAC is easily bypassed as well. In fact, the majority of wontfix exploits has something to do with UAC. > They all expect to be run through an admin powershell/command line. Admin rights will be acquired by using exploits (of which there are many) or by using built-in tools found in the Windows system directory, for example Wscript.exe. No internet connection required. No fetching of external files. You have no say in whether you can allow it to run or not. > you will get a warning before the script is able to gain administrative access. False. You wouldn't even know. Not a visible commandline window to be seen. It's all silent. A well-developed exploit will delete most of it's traces. This is all pretty basic knowledge in the sec research community. Test it and verify it for yourself. I test hardening configurations using a Windows VM.
- howinteresting 5y agoUAC is generally quite easy to bypass and not a real security boundary.