Netskope Threat Labs

DisableDefender

ATP Sandbox Adv. HeuristicsAV

This generic detection identifies attempts to disable Windows Defender and other security software so that malware can operate without detection.

First seen
April 2022
Last seen
October 2026
Alert Name
Application.Hacktool.DisableDefender.D
Application.Hacktool.DisableDefender.E
Application.Hacktool.DisableDefender.F
Application.Hacktool.DisableDefender.G
ByteCode-MSIL.Trojan.DisableDefender
Dropped:Application.Hacktool.DisableDefender.F
Script-BAT.Ransomware.DisableDefender
Script-Registry.Trojan.DisableDefender
Win32.Ransomware.DisableDefender
Win32.Trojan.DisableDefender