Threat actors are increasingly abusing Microsoft Defender Antivirus exclusions to keep malicious files outside the reach of endpoint scans, and a little-known policy setting can conceal those exclusions from administrators using normal management tools.
Huntress researchers found that attackers can combine broad Defender exclusions with the HideExclusionsFromLocalAdmins setting, creating a stealthy defense-evasion path that leaves malicious activity unscanned while obscuring evidence of the change.
Microsoft Defender Antivirus (MDAV) exclusions are legitimate administrative controls intended to prevent performance or compatibility problems for trusted software.
They can exclude a process, file path, file extension, or IP address from specific antivirus inspection functions.
But an attacker who has obtained local administrator or higher privileges can abuse them to suppress real-time, scheduled, and on-demand scanning for locations where malware is staged or executed.
Path and extension exclusions present the highest risk in an intrusion.
A path exclusion targeting a temporary directory, user profile location, or an entire drive can allow an adversary to download, unpack, and execute payloads without Defender inspection.
Extension exclusions can similarly create blind spots for malicious binaries, scripts, archives, or renamed payloads.
Microsoft notes that exclusions may be configured through Intune, MDM, Group Policy, PowerShell, or WMI, broadening the number of administrative interfaces attackers can misuse after privilege escalation.
When Defender-managed exclusions are configured, related settings are ultimately written to the Windows Registry.
This makes registry telemetry especially valuable for detection regardless of the initial configuration method.
The critical concealment feature is the HideExclusionsFromLocalAdmins policy value located at:
HKLMSOFTWAREPoliciesMicrosoftWindows DefenderHideExclusionsFromLocalAdmins
When enabled, the setting does not remove existing exclusions. Instead, it prevents them from appearing through ordinary local administrative queries, including Get-MpPreference, and can also prevent visibility through Registry Editor under Microsoft’s current documentation.
Huntress further observed that the limitation can affect SYSTEM-level PowerShell queries, potentially weakening security products or scripts that rely only on the Defender command-line interface to audit exclusions.
This tradecraft is attractive because it is less conspicuous than turning Microsoft Defender access off altogether. A disabled antivirus service is likely to trigger security alerts, policy compliance failures, or immediate analyst scrutiny.
An exclusion, however, can appear operationally plausible particularly on servers, developer endpoints, or systems running business applications that require legitimate AV exceptions.
Huntress said that, Microsoft Defender exclusions can be created through PowerShell cmdlets such as Set-MpPreference and Add-MpPreference, through the MSFT_MpPreference WMI class, through Group Policy, or by altering policy-backed Registry values.
Microsoft Defender Exclusions
The technique has precedent in real-world campaigns. GootKit previously added Defender path exclusions through WMI, while the destructive WhisperGate malware used PowerShell to add an exclusion for the C: drive.
Such activity maps to MITRE ATT&CK technique T1562.001: Impair Defenses: Disable or Modify Tools, which covers adversaries modifying security controls to avoid detection of malware and related activity.
Defenders should not rely exclusively on Get-MpPreference or the Windows Security interface to validate Defender configuration.
Instead, incident responders should collect and alert on Registry changes involving both Defender’s exclusion keys and the policy-backed exclusion location:
HKLMSOFTWAREMicrosoftWindows DefenderExclusions
HKLMSOFTWAREPoliciesMicrosoftWindows DefenderExclusions
Security teams should also investigate any modification to HideExclusionsFromLocalAdmins, especially when it occurs shortly before or after suspicious PowerShell, WMI, Group Policy, remote administration, credential-access, or payload-staging activity.
Huntress recommends registry-level telemetry because every exclusion mechanism ultimately produces a registry change that can be monitored.
Organizations should minimize standing local administrator privileges, centrally manage Defender policy through Intune or Group Policy, and explicitly review whether local administrators are permitted to merge locally created exclusions with managed configuration.
Microsoft documents that locally defined exclusions are merged with centrally deployed settings by default, while managed exclusions take precedence during conflicts.
Administrators should also establish a baseline of approved exclusions and flag broad entries such as root-drive paths, temporary directories, user-writable folders, wildcard extensions, and unexpected IP exclusions.
Any hidden exclusion should be treated as an investigation trigger rather than an assumed administrative preference.
The key lesson is that antivirus status alone is not a reliable measure of endpoint protection.
Defender may remain enabled and appear healthy while attackers quietly carve out unscanned locations for malware execution and then hide those exceptions from the very administrators tasked with finding them.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

