Slackbot
04/12/2022, 12:13 PMSlackbot
05/12/2022, 2:07 PMSlackbot
05/13/2022, 4:46 PMSlackbot
05/13/2022, 5:29 PMSlackbot
05/16/2022, 8:41 PMSlackbot
05/24/2022, 8:03 AMSlackbot
05/25/2022, 7:49 AMSlackbot
05/26/2022, 5:08 PMSlackbot
07/12/2022, 6:13 PMBalint Oberrauch
10/07/2022, 9:08 AMSlackbot
10/13/2022, 8:37 AMSalim Hurjuk
11/29/2022, 7:42 AMSlackbot
12/06/2022, 7:31 AMSlackbot
12/12/2022, 2:14 PMSlackbot
12/15/2022, 10:43 PMSlackbot
02/07/2023, 10:40 AMSlackbot
03/27/2023, 1:50 PMSlackbot
05/30/2023, 10:06 PMDave Brett
07/22/2023, 7:51 PMSlackbot
08/23/2023, 1:29 PMSlackbot
08/30/2023, 2:50 PMNick Casagrande
08/30/2023, 3:16 PMSlackbot
10/17/2023, 2:55 PMSlackbot
02/16/2024, 1:37 AMJonathan Pitre
01/14/2025, 6:59 PMMatt Sliva
01/24/2025, 6:54 PMJoshua Szántó
01/30/2025, 8:27 PMpsexec -s restOfCommandHere
and PowerRun.exe
and neither have been successful.
EDIT: this seems to work Set-MpPreference -DisableRealtimeMonitoring $true
(PowerShell)
EDIT2: bah, very mixed resultsJoshua Szántó
01/30/2025, 9:33 PMJoshua Szántó
01/30/2025, 10:45 PMSafe Mode with Command Prompt
2. Launch regedit
and modify registry keys HKLM\SYSTEM\CurrentControlSet\Services\WinDefend
, ..\MDCoreSvc
, ..\wscsvc
for value Start
to data 4
3. Modify aforementioned registry keys' permissions to add Everyone
Deny
for any ACL matching Write|Modify|Delete
wscsvc
is Security Center
, but it doesn't appear to impact accessing the Security Center dashboard let alone reporting of things like Windows Firewall and everything else. This service is what also tries to heal WinDefend
and MDCoreSvc
. You don't actually have to include making any modifications to wscsvc
, but not doing so will result in several minutes after every bootup of wscsvc
launching MsMpEng.exe
a million times (stops after a few minutes).
If you are imaging, there are various opportunities to apply these edits before the OS actually boots. But, if not using an imaging tool, so far unsure if there's even a way to script this given all the obstructions that exist in non-Safe Mode Windows. Also, IF NOT USING a third party antivirus, re-enabling it will be a PITA because of the need to automate it and obstructions involved.James Terrell
04/01/2025, 2:10 PM