HomeSecurityNew DefenderWrite tool allows insertion of malicious DLL files

New DefenderWrite tool allows malicious DLL files to be imported

A new tool called DefenderWrite exploits whitelisted Windows programs to bypass protections and write arbitrary files to antivirus executable folders, potentially allowing malware to persist.

See also: Notepad++: DLL Hijacking Vulnerability Allows Code Execution

DefenderWrite
New DefenderWrite tool allows malicious DLL files to be imported

Developed by cybersecurity expert Two Seven One Three, the tool introduces a new technique for penetration testers and red teams to drop payloads in highly protected locations without requiring kernel-level access.

This development highlights the ongoing challenges for virus self-protection mechanisms, where folders hosting AV executables are typically protected from modifications to prevent tampering.

By identifying system programs that antivirus vendors have whitelisted for updates and installations, attackers can exploit these exceptions to inject malicious DLLs, turning their own AV safeguards against them.

The release of the tool, shared via GitHub, has sparked discussions about the balance between functional needs for AV software and security risks in corporate environments.

The key innovation behind DefenderWrite lies in systematically scanning Windows executables to find those that have permission to access AV folders. By enumerating all .exe in directories like C:\Windows, it then uses process creation and remote DLL injection to test their ability to write to protected paths.

See also: RVTools site hacked and distributed Bumblebee malware

New DefenderWrite tool allows malicious DLL files to be imported
New DefenderWrite tool allows malicious DLL files to be imported

A custom DLL performs the file write operation and reports success or failure, allowing the tool to detect exploitable processes like msiexec.exe without triggering defenses. In testing on Windows 11 24H2 with Microsoft Defender version 4.18.25070.5-0, the method detected four such programs: msiexec.exe, Register-CimProvider.exe, svchost.exe , and lsass.exe.

This approach extends beyond Microsoft Defender. Similar whitelisting vulnerabilities have been confirmed in BitDefender, TrendMicro Antivirus Plus , and Avast, though specific details remain unknown to encourage independent verification.

DefenderWrite supports basic parameters for targeted operations, such as TargetExePath for the host executable, FullDLLPath for the injected library, and FileToWrite for the target path within the AV folder. An optional “c” flag simplifies copying the DLL to the specified location remotely.

The binary file comes with a PowerShell script, Run_Check.ps1, which automates the scanning of executable files in C:\Windows and recording those that are whitelisted for further exploitation.

See also: Defendnot tool disables Microsoft Defender

New DefenderWrite tool allows malicious DLL files to be imported

Users can customize the scenario for their environment, making it suitable for red team simulations or defensive assessments.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS