Microsoft didn't sandbox Windows Defender, so I did (2017)
blog.trailofbits.com
blog.trailofbits.com
Microsoft didn’t sandbox Windows Defender, so I did - https://news.ycombinator.com/item?id=14909759 - Aug 2017 (43 comments)
Hostile code scanners need to look at a lot, but they don't need permission to write much. If sandboxed that way, attacks aimed at the code scanner don't do much.
https://learn.microsoft.com/en-us/defender-endpoint/sandbox-...
Now with ongoing changes due to Secure Future Initiative, it will become so, Windows is already going into app sandboxing[3], Virtualization-based Security[2], Pluton requirements[1], and plenty others[0], I would expect it to eventually be enabled by default.
[0] - https://learn.microsoft.com/en-us/windows-hardware/design/de...
[1] - https://learn.microsoft.com/en-us/windows/security/hardware-...
[2] - https://learn.microsoft.com/en-us/windows-hardware/design/de...
[3] - https://blogs.windows.com/windowsdeveloper/2023/06/14/public...
default for what? a non-existent bundled anti-virus scanner?
you don't need to sandbox something that doesn't exist
selinux is enabled by default on RHEL, apparmor is on by default for ubuntu/debian (so "most" is covered)
seccomp()/unshare() are necessarily application specific but still very heavily used (Chrome, flatpak, systemd, ...)
>.....other than Android and ChromeOS.
Red-Hat has some of them turned on, not the full stuff, otherwise I would be out of work in SecDevOps security assements.
https://ubuntu.com/tutorials/install-ubuntu-desktop#6-type-o...
[0] The software I'm using does a scan over a few hundred thousand files to read file headers. Without windows defender it takes about 30 seconds, but with defender it takes about 300.
In my environment we have to add exceptions for Developers git folders for the realtime scanning for a similar reason. Apps with large numbers of small files or high frequency writes of smalls files, like temp files during the build process, need to be exempted unless you’re willing to pay the performance penalty for the security.
I'm going to give dev drive a go, but forgive me for being sus for enabling a feature for a problem that MS seem to have caused.
Sorry, but wanting to disable Defender entirely for some ultra Edge Case ist Just dumb.
> for some ultra Edge Case ist Just dumb
By ultra edge case you mean the application that I spend as much time in as my IDE for my job?
If you keep your system regularly updated, it's less of a problem, but I often help people who basically never update or leave their computer on long enough for Defender to do complete scans. After a certain point it basically becomes impossible to update because defender fights update and chrome and discord and etc etc etc, for access to the files and you end up with the cpu and harddrive maxed out for a couple of days before everything completes.
You can set exclusions of course, but it does get tedious because every time you have a new project you need to add exclusions for its folder and the toolchain. Then every time a toolchain is updated (eg .../gcc/11.5 changes to gcc/11.5.2 you have to enter the 20 new exe exclusions and of course windows won't let you mass delete the old ones so it's click->confirm->click->confirm x50).
I might not do it myself but I can see why someone would just say "enough is enough".
[0] https://learn.microsoft.com/en-us/powershell/module/defender...
Sometimes a big blunt hammer does the trick!
(DevDrive + Defender's "performance mode")
Another option is to enable "Smart App Control" this will permanently disable defender but you will only be able to run signed executables, and to turn it on you must have never run any unsigned executables in the past (or reformat your hard drive).
There's an app called DefenderControl that will disable it, as well, using various methods.
You can also install some other anti-virus software, but you can't make your own -- they need to be signed with a special key.
A fun bit of trivia: defender doesn't turn itself on until after the "out of box experience" is finished, under the rationale that users can't install any malware until they can use the computer. Thus you can run defender disabling scripts/programs from a customized installer without them getting nuked by defender.
It does not work. You can disable _some things_ , but not the whole.
Just run
Get-ChildItem @( "C:\Windows\servicing\Packages\Microsoft-Windows-GroupPolicy-ClientTools-Package.mum", "C:\Windows\servicing\Packages\Microsoft-Windows-GroupPolicy-ClientExtensions-Package.mum" ) | ForEach-Object { dism.exe /online /norestart /add-package:"$_" }