New ‘Defendnot’ tool tricks Windows into disabling Microsoft Defender
'Defendnot' is a new utility that can disable Microsoft Defender on Windows devices by registering a phony antivirus program, even if there isn't any actually installed.
The method makes advantage of an undocumented Windows Security Center (WSC) API, which antivirus software uses to inform Windows that it has been installed and is now in charge of the device's real-time security.
To prevent conflicts from running several security apps on the same device, Windows immediately disables Microsoft Defender when an antivirus product is registered.
This API is abused by the Defendnot utility, developed by researcher es3n1n, which registers a phony antivirus program that passes all of Windows' validation checks.
The tool is built on a prior project called no-defender, which spoof regi...

