Ross ROSS = Recommend OSS · open-source software intelligence for agents

es3n1n/defendnot

An even funnier way to disable windows defender (through WSC api) observed · 2026-08-28

github.com/es3n1n/defendnot · homepage · C++ · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

85/100

  • Activity 97
  • Release rhythm 98
  • Longevity 34
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: 26.5
  • age_days: 483
  • days_rel: 18
  • days_push: 18
  • n_releases_24m: 7

Full methodology

Adoption not part of the score

3636 stars · 297 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

defendnot is a C++ Windows utility that disables Windows Defender by registering a fake antivirus product through the Windows Security Center (WSC) API. It runs as a loader binary or PowerShell one-liner and can optionally register a fake firewall and strip additional Defender policies.

Use cases

  • disable windows defender on my machine
  • register a fake antivirus via WSC api
  • turn off defender real-time protection programmatically
  • remove windows defender from security center
  • security research on windows defender tampering

When to choose

  • you need to disable Windows Defender on a Windows machine you control, e.g. for testing or lab environments
  • you want a WSC-API-based approach rather than registry or service hacks
  • you want optional extras like fake firewall registration and extra Defender policy stripping

When to avoid

  • you need a legitimate antivirus solution or endpoint protection
  • you cannot or will not temporarily disable tamper protection and Smart App Control first
  • you need the tool to survive reboots without keeping binaries on disk
  • using it to facilitate malware distribution or any illegal activity

Facets

cli-tool · maturity active

security cli security windows developer-tools windows windows-defender wsc-api antivirus-registration security-research offensive-tooling

2 sources

Member repositories

RepositoryRoleHealth v2
es3n1n/defendnotmain85

For agents

markdown · JSON · MCP: product_card(name="es3n1n/defendnot")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem