Wanna disable Defender when enabled Isolated Core and Tamper protection? Its a bit more trouble- but doable, without ruining Isolated Core/Secureboot etc. Defenders process will run as a unkillable protected service- so new tricks needed. Here we go:
-
Show this thread
-
Ok- tamper protection is easy, just make .bat - run as adm: :again reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WdFilter\Instances\WdFilter Instance" /v altitude /t REG_SZ /d -1 /f goto again Then unload minifilter with process hacker:pic.twitter.com/zVQjBvPuj6
2 replies 4 retweets 30 likesShow this thread -
The registry key will be changed while the minifilter do not protect it, when tamper protection makes the driver load again it cannot attach to volumes nor protect registry keys. Removing it will make it recreate, but invalid altitude do the trick
1 reply 2 retweets 8 likesShow this thread -
Notice now the service is: Protected light(antimalware) Now we cant do anything to the service/process- not even see its open handles.pic.twitter.com/DIKOejF3oL
1 reply 1 retweet 7 likesShow this thread -
Lets start by elevating to SYSTEM- just launch a command prompt, then close process hacker- and run it again from the command prompt. Now process hacker runs as SYSTEMpic.twitter.com/gL8j4O7P4F
1 reply 2 retweets 6 likesShow this thread -
Find the services process again- select the token tab. Right click and disable the two groups: WinDefend Administratorspic.twitter.com/NJ7S6qu6TE
2 replies 1 retweet 8 likesShow this thread -
1 reply 0 retweets 6 likesShow this thread -
Now defender no more constant opens files- it dosnt do anything actually.... If you wanna permanently disable it its easy enough now there is no protection on its files. If you mklink MsMpLics.dll:q nul it will not run on restart- but you loose the isolated core status :S
1 reply 0 retweets 12 likesShow this thread
But secure boot and core isolation is still running finepic.twitter.com/rSIKcaAMVr
-
-
I am surprised that the protected services tokens are not protected.... that seems like bad design... It also means we can impersonate them- here I impersonate SecureSystem:pic.twitter.com/OtQSpfJ72h
2 replies 3 retweets 21 likesShow this threadThanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.