TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

An unexpected journey into Microsoft Defender's signature World

175 pointsby serhack_11 months ago

6 comments

Angostura11 months ago
A note to the author: if you are going to include “ EDR and EPP” in the intro, please spell them out on first use
评论 #40854851 未加载
评论 #40854580 未加载
评论 #40854891 未加载
FrostKiwi11 months ago
Great deep dive! Always wondered about the details around this topic.<p>Did a bit of red teaming around the topic of reverse shells and privilege escalation and was pleasantly surprised, how much Windows Defender catches. Our IT Department recently switched away from a paid McAfee service doing end point security, which failed to detect unauthorized access in many instances.<p>Also, I totally read the intro as &quot;addressing the ERP use-case&quot;
评论 #40858761 未加载
评论 #40856593 未加载
评论 #40857039 未加载
vegadw11 months ago
I wish that on a positive find Defender had a &quot;for the nerds&quot; section that says what exactly was found. Was there a URL Regex match, like this article gives an example for? Tell me that. I get enough false positives that I want to be able to vet them myself, but that&#x27;s hard to do without just trusting the source if all get is a &quot;This has been quarantined&quot; without telling me why beyond a broad class of types of malware.
RachelF11 months ago
Nice big attack surface there. I wonder what&#x27;s to stop someone modifying the vdx virus definition files to include something like Edge.exe or Explorer.exe?
banish-m411 months ago
MDE plan 2 had problems where MS was pushing out under-tested signatures. One time, they pushed out defs that deleted all menu shortcuts for some users, leading them to believe all of their software had been uninstalled.
InDubioProRubio11 months ago
Thaught it would mention at least the slow-down bug, that slows some systems to a crawl as soon as defender scans some folders.