
Bruteforcing Windows Defender Exclusions
Source: YouTube · John Hammond · published Oct 10, 2024 · 25:32
Low-privileged users can discover Windows Defender antivirus exclusions without admin access using a clever command-line technique 0:00.
Key Takeaways:
• Windows Defender exclusions are normally protected and require admin privileges to view 1:38
• The technique uses mpcmdrun.exe with syntax: mpcmdrun.exe -scan -scantype 3 -file "PATH|*" 7:07
• If a path is excluded, Defender outputs "scanning folder was skipped" 10:59
• The "SharpExclusionFinder" tool automates this exclusion discovery process 15:53
• Defenders can detect this technique using Sigma rules that monitor for unusual mpcmdrun.exe patterns 20:00
This technique demonstrates a security concern where attackers can identify unprotected system areas without elevated privileges.
Sources:
- 0:00 Introduction to Windows Defender exclusions vulnerability
- 1:38 Demonstrating admin requirement for viewing exclusions
- 7:07 Explaining the command-line technique
- 10:59 Showing successful exclusion detection
- 15:53 Introduction to SharpExclusionFinder tool
- 20:00 Creating detection rules for defenders
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
peing behind the curtain finding Windows Defender antivirus exclusions this is an article that I saw pop up on Twitter just a bit ago and I thought it was pretty neat and I wanted to share it with you Kudos and credit where credit is due this is put together by a group of security folks friends and security and they've got a little uh table of contents here I'm going to skip over the tldr because I'd like to Showcase it and let's get right into the introduction they say recently we raised an issue on X regarding how low privileged users can access exclusion path set in the Microsoft Defender antivirus Through the Windows event logs so if you're not familiar I've got a Windows 11 virtual machine set up so that we can follow along but look the antivirus exclusions things that come from malwa…