Defense Evasion
AV Service
Antivirus Name
Service Name
Process Name
Enumerating AV solution existing on machine
PS C:\Users\ROG> Get-CimInstance -Namespace root/SecurityCenter2 -ClassName AntivirusProduct
displayName : Windows Defender
instanceGuid : {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
pathToSignedProductExe : windowsdefender://
pathToSignedReportingExe : %ProgramFiles%\Windows Defender\MsMpeng.exe
productState : 393472
timestamp : Thu, 21 Mar 2024 10:45:38 GMT
PSComputerName :Enumerate WinDefender
Disable Windows Defender
Disable Local Firewall
Last updated