2
Windows Defender Anti-virus Bypassed Using Direct Syscalls & XOR Encryption
(cybersecuritynews.com)
This is a most excellent place for technology news and articles.
Wasn’t there something a few months ago about Microsoft handing out secret API calls to developers of other antivirus products so they can quietly disable Defender during the installation of their product? Some guy had this reverse engineered from an installer…
It’s not a secret. It’s a regkey. You need privs to do it though.