A new tool called Defendnot raises serious questions about the security of Microsoft Defender, as it manages to disable through a technical deception: it appears to add another antivirus program, without actually having it installed. In this way, Defender thinks that there is protection from somewhere else.

The method used by Defendnot is based on the abuse of an undocumented Windows Security Center (WSC) API. This API allows antivirus programs to inform Windows that they are taking over protection real-time. When the operating system detects such a product, it automatically disables Defenderto avoid potential “conflicts” between different security applications.
The tool's creator, researcher es3n1n, managed to bypass security mechanisms by registering a virtual antivirus that successfully passes all WSC certification checks, even though there is no real protection.
See also: SSRF Vulnerabilities: What They Are and How to Protect Yourself
Defendnot is based in part on the older no-defender, which used code from a real third-party antivirus to trick WSC. That project was taken down from GitHub after a DMCA request from the antivirus vendor. As explains in a related post, when the project had about 1,500 stars, the antivirus developers filed a DMCA takedown request and took it all down.
Unlike its predecessor, Defendnot creates a virtual antivirus DLL from scratch, thus avoiding copyright issues.
It's worth noting that, normally, the WSC API is protected by technologies like Protected Process Light (PPL) and requires valid digital signatures and other safeguards — however, Defendnot seems to effectively bypass these obstacles as well.
See also: How to detect backdoors in corporate networks? (+ protection tips)
Defendnot: How a research tool “tricks” Microsoft Defender
The Defendnot manages to bypass security controls by injecting its malicious DLL into the trusted and Microsoft-signed Taskmgr.exe. Through this "legitimate" process, the tool can register a virtual antivirus with a fake name, bypassing the operating system's trust check.

Once this false registration is completed, Microsoft Defender is immediately disabled, leaving the system without any active protection.
Defendnot also comes with a special loaderthat reads configuration parameters from the ctx.bin. Through this file, the user can define the brand of the “fake” antivirus, enable or disable WSC registration, and set a detailed logging for research purposes.
To ensure persistence on the system, Defendnot creates an autorun via Windows Task Scheduler, which allows it to start automatically with every reboot or user login to Windows.
Although presented as a research project, Defendnot clearly demonstrates how easily someone can exploit trusted system processes to bypass critical security measures.
See also: What are elevation of privilege vulnerabilities and how to protect yourself
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Defendnot is not just another proof-of-concept; it is a stark reminder that security should never be based solely on the “ good faith assumption ” of the operating system. The ease with which a non-existent antivirus can be listed as “approved” by Windows, without any substantive confirmation of functionality or origin, reveals a structural problem: the ecosystem trusts its own APIs too easily.
While Defendnot is not a direct threat to the average user, it does serve as a warning. If someone can “download Defender” with a few lines of code and without even an exploit, then what’s stopping an organized cybercrime ring from incorporating the same technique into a full malware framework?
Maybe it's time for Microsoft to reconsider stricter authentication checks for products declared in the Windows Security Center. Because if your operating system can be so easily convinced that it's protected... then it's essentially not protected at all.
It is noted that Microsoft Defender now detects Defendnot (“Win32/Sabsik.FL.!ml”) and automatically quarantines it.
Source: www.bleepingcomputer.com
