Defense Evasion

AV Service

The following table contains well-known and commonly used AV software.

Antivirus Name
Service Name
Process Name

Microsoft Defender

WinDefend

MSMpEng.exe

Trend Micro

TMBMSRV

TMBMSRV.exe

Avira

AntivirService, Avira.ServiceHost

avguard.exe, Avira.ServiceHost.exe

Bitdefender

VSSERV

bdagent.exe, vsserv.exe

Kaspersky

AVP<Version #>

avp.exe, ksde.exe

AVG

AVG Antivirus

AVGSvc.exe

Norton

Norton Security

NortonSecurity.exe

McAfee

McAPExe, Mfemms

MCAPExe.exe, mfemms.exe

Panda

PavPrSvr

PavPrSvr.exe

Avast

Avast Antivirus

afwServ.exe, AvastSvc.exe

Enumerating AV solution existing on machine

PS C:\Users\ROG> Get-CimInstance -Namespace root/SecurityCenter2 -ClassName AntivirusProduct


displayName              : Windows Defender
instanceGuid             : {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
pathToSignedProductExe   : windowsdefender://
pathToSignedReportingExe : %ProgramFiles%\Windows Defender\MsMpeng.exe
productState             : 393472
timestamp                : Thu, 21 Mar 2024 10:45:38 GMT
PSComputerName           :

Enumerate WinDefender

Disable Windows Defender

Disable Local Firewall

Last updated