Easy defender disabler: Procmon, processes,04,modules,wdfilter.sys unload reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WdFilter\Instances\WdFilter Instance" /v altitude /t REG_SZ /d -1 /fpic.twitter.com/xDjOFV2j2v
You can add location information to your Tweets, such as your city or precise location, from the web and via third-party applications. You always have the option to delete your Tweet location history. Learn more
what? you changed the state by observing it? it shouldnt be this hard to disable it
Yeah, I was ready to give up and start sifting through procmon logs to figure out how that GP setting was getting reverted.
Only once I enabled the procmon boot log and rebooted once, I noticed that Defender was actually disabled, and it stuck.

Have you turned off tamper protection before disabling AV? That's a must. https://docs.microsoft.com/windows/security/threat-protection/windows-defender-antivirus/prevent-changes-to-security-settings-with-tamper-protection …
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.