Windows Defender - Add exclusion folder programmatically

后端 未结 5 2059
醉梦人生
醉梦人生 2021-01-31 11:56

I was checking out different keyloggers for research purposes and stumbled upon Refog:

https://www.refog.com/keylogger/

This program could catch a lot of system

5条回答
  •  陌清茗
    陌清茗 (楼主)
    2021-01-31 12:29

    After some digging I found the following folder:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths
    

    I cannot add a key there with my user. I get the following error: Cannot create key: You do not have the requisite permissions to create a new key under Paths

    However SYSTEM, WinDefend and TrustedInstaller all have Full Control. The best guess is that they have used something like DevxExec devxexec.exe /user:TrustedInstaller cmd and written the key to the registry.

提交回复
热议问题