mirror of
https://github.com/es3n1n/defendnot.git
synced 2026-10-01 10:01:36 +00:00
feat: add extra-strip.bat (#59)
This commit is contained in:
1
.github/workflows/build.yml
vendored
1
.github/workflows/build.yml
vendored
@@ -59,6 +59,7 @@ jobs:
|
||||
Copy-Item -Path ".\out\$mappedPlatform\defendnot.pdb" -Destination ".\artifacts\$platform\" -Verbose
|
||||
Copy-Item -Path ".\out\$mappedPlatform\defendnot-loader.exe" -Destination ".\artifacts\$platform\" -Verbose
|
||||
Copy-Item -Path ".\out\$mappedPlatform\defendnot-loader.pdb" -Destination ".\artifacts\$platform\" -Verbose
|
||||
Copy-Item -Path ".\extra-strip.bat" -Destination ".\artifacts\$platform\" -Verbose
|
||||
shell: pwsh
|
||||
|
||||
- name: Upload artifacts
|
||||
|
||||
@@ -65,10 +65,16 @@ Optional arguments:
|
||||
--disable-autorun disable autorun task creation
|
||||
```
|
||||
|
||||
## Stripping Defender out further (optional)
|
||||
|
||||
defendnot only registers a fake AV through WSC, but if you want to strip more Defender stuff out, run the optional `extra-strip.bat` as admin after defendnot is active. It disables a bunch more Defender policies in registry: real-time monitoring, behavior monitoring, cloud reporting, signature updates, etc.
|
||||
|
||||
It's a separate script because the keys are finicky and undoing them on `--disable` would mean saving every value first somewhere and writing all of them back, which is _waaay_ more bookkeeping than I feel like implementing.
|
||||
|
||||
## Limitations
|
||||
|
||||
- **Needs to stay on disk:**
|
||||
To keep the AV registration persistent after reboot, defendnot adds itself to autorun. That means the binaries have to remain on your system.
|
||||
To keep the AV registration after reboot, defendnot adds itself to autorun.
|
||||
|
||||
## Writeup
|
||||
|
||||
|
||||
30
extra-strip.bat
Normal file
30
extra-strip.bat
Normal file
@@ -0,0 +1,30 @@
|
||||
:: based on https://github.com/es3n1n/defendnot/issues/49 comments
|
||||
@echo off
|
||||
setlocal
|
||||
|
||||
net session >nul 2>&1
|
||||
if %errorlevel% neq 0 (
|
||||
echo This script needs administrator rights
|
||||
pause
|
||||
exit /b 1
|
||||
)
|
||||
|
||||
reg.exe ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" /v DisableAntiSpyware /t REG_DWORD /d 00000001 /f
|
||||
reg.exe ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" /v DisableAntiVirus /t REG_DWORD /d 00000001 /f
|
||||
reg.exe ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" /v DisableRoutinelyTakingAction /t REG_DWORD /d 00000001 /f
|
||||
reg.exe ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" /v ServiceKeepAlive /t REG_DWORD /d 00000000 /f
|
||||
reg.exe ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableBehaviorMonitoring /t REG_DWORD /d 00000001 /f
|
||||
reg.exe ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableIntrusionPreventionSystem /t REG_DWORD /d 00000001 /f
|
||||
reg.exe ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableIOAVProtection /t REG_DWORD /d 00000001 /f
|
||||
reg.exe ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableOnAccessProtection /t REG_DWORD /d 00000001 /f
|
||||
reg.exe ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableRawWriteNotification /t REG_DWORD /d 00000001 /f
|
||||
reg.exe ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableRealtimeMonitoring /t REG_DWORD /d 00000001 /f
|
||||
reg.exe ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableScanOnRealtimeEnable /t REG_DWORD /d 00000001 /f
|
||||
reg.exe ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Signature Updates" /v DisableUpdateOnStartupWithoutEngine /t REG_DWORD /d 00000001 /f
|
||||
reg.exe ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Signature Updates" /v UpdateOnStartup /t REG_DWORD /d 00000000 /f
|
||||
reg.exe ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\SpyNet" /v DisableBlockAtFirstSeen /t REG_DWORD /d 00000001 /f
|
||||
reg.exe ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\SpyNet" /v SpynetReporting /t REG_DWORD /d 00000000 /f
|
||||
|
||||
echo All done, please restart your machine to apply these changes
|
||||
pause
|
||||
endlocal
|
||||
Reference in New Issue
Block a user