Published on October 1, 2026

Attackers Can Conceal Microsoft Defender Exclusions from PowerShell Queries


Severity

Medium

Detail

Researchers have highlighted a defense-evasion technique that allows attackers to hide Microsoft Defender Antivirus exclusions from standard PowerShell queries and the Windows Security interface. The technique abuses a legitimate Microsoft Defender policy setting, enabling configured exclusions to remain active while becoming invisible to commonly used administrative tools.

Microsoft Defender Antivirus supports exclusions for files, folders, processes, file extensions, and IP addresses to prevent unnecessary scanning of trusted applications and resources. While these exclusions are commonly used for operational purposes, threat actors can abuse them to exclude malicious files or directories from security scans, allowing malware to operate with reduced detection risk.

The research shows that attackers can conceal these exclusions after gaining administrative access to a system. As a result, security administrators relying solely on PowerShell commands such as Get-MpPreference may not see the configured exclusions, potentially delaying detection and incident response activities.

The technique adds an additional layer of stealth to existing malware evasion methods and highlights the importance of validating Defender configurations beyond standard management interfaces.

How?

Microsoft Defender stores exclusion settings in the Windows registry and supports management through PowerShell, Windows Management Instrumentation (WMI), Group Policy, and direct registry modifications. Attackers first create Microsoft Defender exclusions using legitimate administration methods such as Set-MpPreference, Add-MpPreference, Group Policy, WMI, or direct registry modifications.

Once the exclusions have been created, attackers can enable the following registry policy HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\HideExclusionsFromLocalAdmins. Setting the value to 1 causes Defender exclusions to remain fully functional while preventing them from being displayed through PowerShell queries and the Windows Security user interface.

The exclusion entries continue to bypass, real-time protection, scheduled antivirus scans and on-demand antivirus scans. Under these conditions, excluded files, folders, and processes may operate without being inspected by Microsoft Defender.

Researchers noted that several malware families have previously abused Microsoft Defender exclusions to protect malicious payloads.  Although the exclusions are hidden from standard Defender management interfaces, they remain visible through direct inspection of registry locations associated with Defender exclusion policies.

Security teams should therefore supplement PowerShell-based auditing with registry-based validation and monitoring of exclusion-related policy changes.

Conclusion

This technique demonstrates how attackers can abuse legitimate Microsoft Defender configuration settings to conceal antivirus exclusions and reduce visibility into malicious activity. While the method does not exploit a software vulnerability and requires administrative privileges to implement, hidden exclusions can significantly weaken endpoint security controls by preventing Microsoft Defender from scanning selected files, folders, and processes.

Organizations should regularly audit Defender exclusions through both PowerShell and direct registry inspections, monitor modifications to exclusion-related registry keys, and restrict administrative access to Defender policy settings. Security teams should also investigate unexpected exclusions involving broad system paths and configure monitoring solutions to detect attempts to enable the HideExclusionsFromLocalAdmins policy.

Source

https://cyberpress.org/hidden-defender-exclusion-policy/