Wanna disable Defender when enabled Isolated Core and Tamper protection? Its a bit more trouble- but doable, without ruining Isolated Core/Secureboot etc. Defenders process will run as a unkillable protected service- so new tricks needed. Here we go:
-
-
Lets start by elevating to SYSTEM- just launch a command prompt, then close process hacker- and run it again from the command prompt. Now process hacker runs as SYSTEMpic.twitter.com/gL8j4O7P4F
Show this thread -
Find the services process again- select the token tab. Right click and disable the two groups: WinDefend Administratorspic.twitter.com/NJ7S6qu6TE
Show this thread -
-
Now defender no more constant opens files- it dosnt do anything actually.... If you wanna permanently disable it its easy enough now there is no protection on its files. If you mklink MsMpLics.dll:q nul it will not run on restart- but you loose the isolated core status :S
Show this thread -
-
I am surprised that the protected services tokens are not protected.... that seems like bad design... It also means we can impersonate them- here I impersonate SecureSystem:pic.twitter.com/OtQSpfJ72h
Show this thread
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.