Last seven days
- First activity
- Oct 2, 2026
- Last activity
- Oct 3, 2026
- Feed role
- C2 / Distribution
- Host form
- 1 IP / 3 hostnames
DefendNot is a Windows defense-evasion tool that abuses Windows Security Center antivirus-registration functionality to register a fraudulent antivirus product.
Profile source: Mallory opens in a new tabDefendnot
DefendNot is a Windows defense-evasion tool that abuses Windows Security Center antivirus-registration functionality to register a fraudulent antivirus product. This can cause Microsoft Defender to disable itself to avoid a perceived conflict with another security product. The tool has been associated with loading or injecting its payload into Task Manager and interacting with Windows Security Center antivirus-status interfaces. It can also be used alongside scheduled-task or autorun persistence mechanisms. DefendNot originated as a research tool demonstrating weaknesses in the Windows Security Center trust model, but has been repurposed in malware operations to neutralize Microsoft Defender before deployment of follow-on payloads. It has been observed in campaigns targeting Windows users and organizations in Russia, including operations delivering Amnesia RAT and Hakuna Matata-derived ransomware.
C2 tracking
Derp observations, rolling seven-day window
Samples
04a811a447f78c2abfd60d8562c4be77104ca29a3dcf9a8e59b398cb517224e4 31762d7f013cde2231033efba13a178872d8bce2ce00b0df0d95109e628f0cd5 50b1283704d52d9980b7f7921b915f4001fcc6bb762b47c5a1018863027ba1cd 8ffc11c33ccb65ae85034ac9987a0e036acd0d05905f1a4383d525eead2bb65f cc9cc54495ecd04859c14b69dae5cb732782593e0ff34299bd0a9e677939b895 515bf107c0095cdfd5b05b30cd6044a69338d27acb47e2c1e7097a83d46a6e8e 790a55c929ccdce6d34b811301121fe7ebf2a35b2fddbe8736bc582b23b91a15 7c04a11b72485957f38a65a92666de7d0a6f80fee78e45638a5db5505ae318e1 8d5d913136a711beb8d1053c63615027925a7726dc030c16eff8e9056ca0f00f 926974c663023c91d45a81f0770501c1c4a0dcd84579645986f31bc5cfe74695 MITRE ATT&CK
Reporting
DefendNot, a Windows defense-evasion tool, abuses Windows Security Center (WSC) antivirus-registration interfaces to present itself as a third-party antivirus product. Because Microsoft Defender normally transitions to passive mode when WSC recognizes another antivirus provider, the technique can reduce or suppress Defender protection without deploying a legitimate competing security product. DefendNot 1.6.0 registers its default fake provider as dnot.sh and uses interfaces including IWscAVStatus4 methods such as Register, UpdateStatus, RegisterAV, and UpdateStatusAV. Defenders can hunt for DefendNot through its execution artifacts, DLL loading or injection into Task Manager, scheduled-task persistence, Security Center antivirus-provider registry modifications, and Microsoft Defender policy tampering. Relevant telemetry includes Windows Security and Defender Operational logs and Sysmon events covering process activity, module loads, scheduled tasks, and registry changes; organizations should investigate unexpected WSC antivirus registrations, particularly where no approved endpoint-security product is installed.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.