mandiant / mandiant/VM-Packages

Disable Tamper Protection and Windows Defender

Open
#696 5 comments 0 reactions 0 assignees View on GitHub
:cyclone: COMMANDO-VM :cyclone: FLARE-VM :grey_question: discussion
Dominant language
PowerShell
Stars
246
Forks
98
Avg merge
9h 30m
Merged PRs (30d)
7

Description

Disable Tamper Protection and Windows Defender, preferably via Group Policy. Resources:
* Disabling Tamper Protection
* https://support.microsoft.com/en-us/windows/prevent-changes-to-security-settings-with-tamper-protection-31d51aaa-645d-408e-6ce7-8d7f8e593f87
* https://www.tenforums.com/tutorials/123792-turn-off-tamper-protection-windows-defender-antivirus.html
* Disabling Windows Defender
* https://stackoverflow.com/questions/62174426/how-to-permanently-disable-windows-defender-real-time-protection-with-gpo
* https://www.windowscentral.com/how-permanently-disable-windows-defender-windows-10
* https://github.com/jeremybeaume/tools/blob/master/disable-defender.ps1
* https://lazyadmin.nl/win-11/turn-off-windows-defender-windows-11-permanently/

@mandiant/flare-vm commando-vm should we add this to the debloat package?

In flare-vm the focus is on Windows 10 and we would like to automate this step that are currently doing manually.

Contributor guide

Open the contributing guide

Research direction

Start by reviewing the debloat package and the referenced disable-defender.ps1 script, then compare the linked Group Policy resources for Windows 10. Confirm how FLARE-VM currently performs this manual step and whether the change belongs in the debloat package; done means both protections are handled by the automated installation flow.

Written by the indexing model from the issue text.

Assessment

Tech stack
powershell
Domain
operating-systems, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.