Under Computer Configuration > Administrative Templates > Windows Components > Microsoft Defender Antivirus
- Turn off Microsoft Defender Antivirus -> set to Enabled
Under Computer Configuration > Administrative Templates > Windows Components > Microsoft Defender Antivirus > Real-Time Protection - Turn on behavior monitoring -> set to Disabled
- Monitor file and program activity on your computer -> set to Disabled
- Turn on process scanning whenever real-time protection -> set to Disabled
- Turn on behavior monitoring -> set to Disabled
Restart the computer and Real-time protection should be disabled permanently (until you reverse the same settings through gpedit.msc at least).Alternatively, if you run windows server as your workstation OS, you can perform an uninstall using Remove-WindowsFeature from powershell.
The old gpedit tricks don't really work anymore in my experience.
Having everyone easily disable Windows Defender will not lead to a great outcome.
There's a reason malware on Windows has been on a steep decline from the Windows XP days and I'd prefer it to keep it that way.
I really only use this machine for MWII, Halo and Titanfall. It's a glorified Xbox. I even contemplated putting it on a standalone VLAN to 100% physically isolate it from my core net.
Their solution? Make it intentionally complicated, but still possible:
Step 1: Turn your headlight switch off
Step 2: Unbuckle your seatbelt and turn the key to the off position
Step 3: Turn your key to the on position till the seatbelt warning light turns off
Step 4: Buckle and unbuckle the seatbelt three times and end on the unbuckled position
Step 5: Turn your headlight switch on for three seconds and then turn it off
Step 6: Repeat step number 3
Step 7: Wait for the seat belt warning light to turn on and off again then buckle and buckle the seat belt
Seat belts are 100% an immediate habit for me. Driving at any rate of speed without one makes me feel super sketchy and uncomfortable, so the nag is not needed at all.
On my Ford's I would use FORScan to defeat it via the OBD2 port.
I do have a security gateway bypass module for my truck though so hopefully I will be able to start playing around with AlfaOBD soon.
I know it’s not your main point. But anyways.. it does not increase the rhetorical power of your comment.
But also even with the most basic win10, cloud submission (if privacy is no biggie) gets you EDR detections to a point but without the edr console and logs.
When I simulate attacks with defender on, I would spend a lot of time bypassing it but then as soon as I break opsec (e.g.: run whoami.exe) if cloud submission is on I basically burn that technique because the edr in their cloud blacklisted it but with that off I can last as long as I want so long as I don't execute things flagged as malware by the defender on the host (and even then, usually that thing gets blocked not my original technique which I can still reuse).