Windows Defender Antivirus and layered machine learning defenses
blogs.technet.microsoft.com
blogs.technet.microsoft.com
[1] https://twitter.com/BruceDawson0xB/status/940747236614574080
Hell, I've had overly aggressive AV (McAfee) locking files in temp data folders causing performance to falter in running applications (Visual Studio, Pidgin, Outlook, Office).
Why does the end user care about compile times?
Never found an AV which didn't seriously hamper build times, since building often involves a lot of process start/stops and new small files, both of which are kryptonite to AV.
MalwareBytes Enterprise recently got completely uninstalled as it was locking random files during compilation indefinitely. They have a fix but only for the consumer branch.
AFAIK. Certainly for some anti-virus software.
Does this mean that Windows Defender is now something to disable on HIPAA compliant workstations because there is a chance that Defender thinks some medical records look suspicious and it decided to upload them for analysis?
But for the home and small business this stuff is amazing. It really continues the anti-"virus" analogy by effectively creating an immune system comprised of most Windows machines.
Just some food for thought. I never trust any "cloud-based" antivirus solution.
all leading security vendors have cloud based solutions with some of them offering 'private-cloud' based solutions which if was the case what they should be using... I cannot fathom this sort of situation as an real 'accident' and not some other form of misinformation.
if you are not utilizing the global up-to-second cloud-herd communication and technology you are more susceptible to attacks than others that are utilizing them.
I believe the purpose of these solutions is literally economic warfare. We are making it astronomically more expensive to have successful attacks more than _once_ (_if_ security is done right) to occur by implementing cloud based automation and sharing of information.
https://bugs.chromium.org/p/project-zero/issues/detail?id=12...
In any case, it doesn't "run as SYSTEM". The invoking credentials for a process are not necessarily relevant on a kernel like NT. A process can choose modify its security token after process invocation. For e.g. User mode apps, can downgrade their read/write rights, limiting them to a fixed directory, so even if they had exploitable bugs, the damage could be limited. Chrome on windows uses these same protections. I'm sure similar tech exists on competing kernels.
MsMpEng.exe AFAICT runs as a 'system protected process'. Certainly, it looks like there were severe bugs but its not clear where the bugs lie. It could be that the protection mechanism itself is flawed (which would be very bad), or maybe the way it's being used is incorrect, etc etc
Certain parts of an AV product need to run with the top-most privileges. But that component should be relatively lean, and quickly hand off dangerous work to lower-privilege, memory isolated, processes.
Windows Defender has a process called NScript which is a full JavaScript processing engine, running in SYSTEM. A JavaScript engine is inherently complicated enough to have bugs, and running as SYSTEM with no isolation could allow escalating a bug into a full blown code execution just by visiting a web page. None of this is theoretical, it was found and exploited May 2017 [0].
You're correct in saying that Windows does allow more nuanced token control than the full user's context, but I'm yet to read that Windows Defender actually utilises that. None of the previous bugs have been stopped by low-priv style access control, it has been a full SYSTEM leak. Do you have specific information about Windows Defender which suggests they're using voluntary revocation of token privileges?
[0] https://bugs.chromium.org/p/project-zero/issues/detail?id=12...
Sure, just dump the security token for MsMpEng.exe. Here it is: https://pastebin.com/ukMPUWA7
IntegrityLevelIndex is 01, MandatoryPolicy is 0x3 , Privs are a subset of the full list.
https://www.nirsoft.net/kernel_struct/vista/TOKEN.html
https://msdn.microsoft.com/en-us/library/windows/desktop/bb5...
https://msdn.microsoft.com/en-us/library/windows/desktop/bb3...