HomeScience & EnvironmentDefendnot tool can silently...

Defendnot tool can silently disable Microsoft Defender without using malware

All modern Windows PCs come with Microsoft Defender built in. For the unaware, this tool is Windows’ native antivirus. 

Over time, it has matured into a reliable security tool capable of blocking a wide range of threats. However, a tool called Defendnot can shut down Microsoft Defender completely, without exploiting a bug or using malware. It simply convinces Windows that another antivirus is already running.

The implications are serious. This tool does not break into the system or use advanced code injection. It uses Windows features the way they were designed to be used. And that makes the problem harder to detect and harder to fix.

Join the FREE “CyberGuy Report”: Get my expert tech tips, critical security alerts and exclusive deals, plus instant access to my free “Ultimate Scam Survival Guide” when you sign up!

Windows software on a PC (Kurt “CyberGuy” Knutsson)

The tool works by pretending to be an antivirus

Windows is built to avoid running multiple antivirus products at once. When a third-party antivirus registers itself, Windows disables Microsoft Defender to prevent conflicts. Defendnot exploits this system using an undocumented API that security software uses to communicate with the Windows Security Center.

The tool registers a fake antivirus that appears legitimate to the system. It uses a dummy DLL and injects it into Task Manager, a trusted Windows process. By operating inside this signed process, Defendnot avoids signature checks and permission blocks. Once the fake antivirus is registered, Windows disables Microsoft Defender without warning or confirmation.

WINDOWS 10 SECURITY FLAWS LEAVE MILLIONS VULNERABLE

No security alert is shown to the user. No visible changes are made to indicate that the system is unprotected. Unless someone checks manually, the machine remains open to attacks with no real-time protection running.

The tool also includes options to set a custom antivirus name, enable logging and configure automatic startup. It achieves persistence by creating a scheduled task that runs whenever the user logs in.

person typing on laptop

Windows software on a laptop (Kurt “CyberGuy” Knutsson)

WINDOWS DEFENDER VS ANTIVIRUS SOFTWARE: FREE PROTECTION FALLS SHORT

From GitHub takedown to a fresh build

Defendnot is based on an earlier project called No-Defender. That project used code from an actual antivirus product to fake registration. It gained attention quickly and was removed after a copyright complaint from the vendor whose code had been reused. The developer took the project down and walked away from it.

With Defendnot, the creator rebuilt the core features using original code. This version avoids copyright issues and uses a new method to achieve the same effect. It does not rely on another antivirus or third-party binaries. It was written from scratch to demonstrate how simple it is to manipulate Windows security from inside the system.

Microsoft Defender currently flags the tool as a threat. It detects and quarantines it under the name Win32/Sabsik.FL.!ml. However, the fact that it works at all points to a weakness in how Windows handles antivirus registration and trust.

WHAT IS ARTIFICIAL INTELLIGENCE (AI)?

laptop on a desk

Windows laptop showing the home screen (Kurt “CyberGuy” Knutsson)

DOUBLECLICKJACKING HACK TURNS DOUBLE-CLICKS INTO ACCOUNT TAKEOVERS

6 ways to protect yourself from malicious programs

While Defendnot is a research project, there’s a chance that similar tools are already out there and could be used to compromise your PC. Here are a few tips to help you stay safe:

1. Use strong antivirus software: Even with regular updates, Windows systems can be left exposed by tools like Defendnot that silently disable built-in defenses. A strong third-party antivirus with real-time protection and frequent updates provides essential backup security. Look for solutions with real-time protection and frequent updates to tackle emerging threats. Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android and iOS devices.

2. Limit exposure: Many exploits rely on user interaction, such as clicking a shady link, downloading a compromised file or mounting an untrusted virtual disk. Stick to reputable websites, avoid opening unsolicited email attachments and use a browser with built-in security features (like Microsoft Edge or Chrome with Safe Browsing enabled).

3. Avoid running unexpected commands: Never paste or run commands (like PowerShell scripts) you don’t understand or that were copied from random websites. Attackers often trick users into unknowingly running malware this way.

4. Keep your software updated: Regularly update your operating system, browsers and all software applications. Updates often include patches for security vulnerabilities that malware can exploit.

5. Use two-factor authentication (2FA): Enable 2FA on all your accounts. This adds an extra layer of security by requiring a second form of verification, making it harder for attackers to gain access even if they have your password.

6. Invest in personal data removal services: Even with strong device security, your personal information may still be exposed online through data brokers and people-finder sites. These services collect and publish details like your name, address and phone number, making you an easier target for identity theft or phishing. Automated data removal services track down these sites and submit removal requests on your behalf, helping to reduce your digital footprint and increase your online anonymity. While they can’t erase every trace of your information, they make it significantly harder for attackers to find and exploit your personal data, which saves you time and reduces unwanted spam in the process.

While no service promises to remove all your data from the internet, having a removal service is great if you want to constantly monitor and automate the process of removing your information from hundreds of sites continuously over a longer period of time. Check out my top picks for data removal services here.

Get a free scan to find out if your personal information is already out on the web.

RELENTLESS HACKERS ABANDON WINDOWS TO TARGET YOUR APPLE ID

Kurt’s key takeaway

Defendnot points to a bigger issue with how Windows handles security. It takes a feature meant to prevent software conflicts and turns it into a way to completely disable protection. The system assumes any registered antivirus is legitimate, so if attackers can fake that, they get in without much resistance.

We often think of security as blocking the bad and trusting the good. But this case shows what happens when that trust is misplaced. Defendnot doesn’t sneak past Windows defenses. It walks right in using valid credentials. The solution isn’t just more patches or stronger malware signatures. What we need is a smarter way for systems to tell what is actually safe.

CLICK HERE TO GET THE FOX NEWS APP

Do you think companies like Microsoft need to rethink how Windows handles antivirus registration and trust, given that tools like Defendnot can so easily disable built-in protections without using malware or exploiting a bug? Let us know by writing us at Cyberguy.com/Contact.

For more of my tech tips and security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter.

Ask Kurt a question or let us know what stories you’d like us to cover.

Follow Kurt on his social channels:

Answers to the most-asked CyberGuy questions:

New from Kurt:

Copyright 2025 CyberGuy.com. All rights reserved.

Source link

- A word from our sponsors -

spot_img

Most Popular

More from Author

Why We Are Going to the Fastest-Melting Glacier

new video loaded: Why We Are Going to the Fastest-Melting GlacierHow...

Majority of investors planning to boost portfolios in 2026, survey finds

Your support helps us to tell the storyFrom reproductive rights to...

Gold and silver prices broke all previous records

Gold, silver, and platinum hit record highs on Friday, as...

Challenge: Only a person with 20/20 vision can spot the summer drink within 12 seconds |

Amidst the twinkling lights and cozy stalls of a delightful...

- A word from our sponsors -

spot_img

Read Now

Why We Are Going to the Fastest-Melting Glacier

new video loaded: Why We Are Going to the Fastest-Melting GlacierHow much time does the Thwaites Glacier in Antarctica have left? Our reporter Raymond Zhong and our photographer Chang W. Lee are joining scientists and engineers who measure how much sea levels could rise as a result...

Majority of investors planning to boost portfolios in 2026, survey finds

Your support helps us to tell the storyFrom reproductive rights to climate change to Big Tech, The Independent is on the ground when the story is developing. Whether it's investigating the financials of Elon Musk's pro-Trump PAC or producing our latest documentary, 'The A Word', which shines...

Gold and silver prices broke all previous records

Gold, silver, and platinum hit record highs on Friday, as speculative momentum and thinning year-end liquidity powered the precious metals, along with markets pricing in more US rate cuts, and rising geopolitical tension. ...

Challenge: Only a person with 20/20 vision can spot the summer drink within 12 seconds |

Amidst the twinkling lights and cozy stalls of a delightful Christmas market, a refreshing summer surprise lies in wait, daring onlookers to uncover it in just 12 seconds. This visual trickery invites you to sharpen your perception, as your mind is led to expect only seasonal...

2025 likely to be UK’s hottest year on record, says Met Office

Mark PoyntingClimate researcherEPARising temperatures in the UK will become "the new normal", a leading government climate adviser has warned, as she called for more to be done to prepare for the impacts of climate change.It comes as the Met Office revealed 2025 was on course to be...

Perry Bamonte, guitarist for The Cure, dies after “short illness” at 65

Perry Archangelo Bamonte, longtime guitarist and keyboardist for the influential goth band The Cure, has died. He was 65.The band announced his death on their official website on Friday."It is with enormous sadness that we confirm the death of our great friend and bandmate...

Stocks making the biggest moves midday: FCX, CPNG, TGT

Check out the companies making the biggest moves midday: Freeport-McMoRan — The miner rose 3.1% as gold and other metals scaled to record levels. Target — The retailer rose more than 1% after the Financial Times reported, citing sources, that hedge fund Toms Capital Investment Management made...

Global Capital Is Doubling Down On NCR’s Commercial Assets; What’s Fuelling The Rush? | Real Estate News

Last Updated:December 27, 2025, 15:42 ISTNet office absorption in NCR jumped 61% year-on-year in 2024, the sharpest increase among major cities, to touch 9.5 million sq. ft.Of the $8.87 billion in real estate investments that entered India in 2024, global investors accounted for nearly two-thirds.Delhi-NCR has entered...

Apple fixes zero-day vulnerabilities in emergency security update

NEWYou can now listen to Fox News articles! Apple has released emergency security updates to fix two zero-day vulnerabilities that attackers actively exploited in highly targeted attacks. The company described the activity as an "extremely sophisticated attack" aimed at specific individuals. Although Apple did not identify...

Prince Harry, Meghan lose key team member responsible for royal truce

Prince Harry and Meghan have lost an important member of their team, who played an instrumental role in cracking...

AAA says a gallon hits 4-year low as holiday travel starts

Customers at the GasWay Xpress Mart at 1120 Erie Blvd. pump gas on Wednesday, Dec. 3, 2025, in Schenectady, N.Y. Lori Van Buren | Albany Times Union | Hearst Newspapers | Getty ImagesHoliday road-trippers are feeling some relief at the pump this year.The average price of unleaded...