Wanna disable Defender when enabled Isolated Core and Tamper protection? Its a bit more trouble- but doable, without ruining Isolated Core/Secureboot etc. Defenders process will run as a unkillable protected service- so new tricks needed. Here we go:
-
Show this thread
-
Replying to @jonasLyk
Did you try unloading the minifilter driver with Fltmc.exehttps://docs.microsoft.com/en-us/windows-hardware/drivers/ifs/development-and-testing-tools …
1 reply 0 retweets 3 likes -
-
-
Replying to @0daydorpher
no- that would be a bit too easy, i also tried sc stop filter
2 replies 0 retweets 1 like -
-
Replying to @0daydorpher
you talking about changing the altitude? That only works because I do it while its not proceted by the filter
1 reply 0 retweets 1 like -
Replying to @jonasLyk
No i thought, destroying the filter manager service, as it loads the filter, might work But just resulted in unbootable
1 reply 0 retweets 1 like
Replying to @0daydorpher
one could also argue that unloading it from pid 4 do seem to easy...but it works :)
11:40 AM - 21 Jan 2021
0 replies
0 retweets
1 like
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.