Bruteforcing Windows Defender Exclusions

Bruteforcing Windows Defender Exclusions

Source: YouTube · John Hammond · published Oct 10, 2024 · 25:32

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Low-privileged users can discover Windows Defender antivirus exclusions without admin access using a clever command-line technique 0:00.

Key Takeaways:
• Windows Defender exclusions are normally protected and require admin privileges to view 1:38
• The technique uses mpcmdrun.exe with syntax: mpcmdrun.exe -scan -scantype 3 -file "PATH|*" 7:07
• If a path is excluded, Defender outputs "scanning folder was skipped" 10:59
• The "SharpExclusionFinder" tool automates this exclusion discovery process 15:53
• Defenders can detect this technique using Sigma rules that monitor for unusual mpcmdrun.exe patterns 20:00

This technique demonstrates a security concern where attackers can identify unprotected system areas without elevated privileges.

Sources:

  • 0:00 Introduction to Windows Defender exclusions vulnerability
  • 1:38 Demonstrating admin requirement for viewing exclusions
  • 7:07 Explaining the command-line technique
  • 10:59 Showing successful exclusion detection
  • 15:53 Introduction to SharpExclusionFinder tool
  • 20:00 Creating detection rules for defenders

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

peing behind the curtain finding Windows Defender antivirus exclusions this is an article that I saw pop up on Twitter just a bit ago and I thought it was pretty neat and I wanted to share it with you Kudos and credit where credit is due this is put together by a group of security folks friends and security and they've got a little uh table of contents here I'm going to skip over the tldr because I'd like to Showcase it and let's get right into the introduction they say recently we raised an issue on X regarding how low privileged users can access exclusion path set in the Microsoft Defender antivirus Through the Windows event logs so if you're not familiar I've got a Windows 11 virtual machine set up so that we can follow along but look the antivirus exclusions things that come from malwa…