Is there a way to limit windows defender for reporting only?

D

DoubleAka

I am performing an experiment in a cyber testbed which include an emulation of infection 3 windows working stations (Windows 10, Windows 10, Windows 11). Since this attack is known to windows defender it automatically quarantine the malicious files. In order to perform the experiment properly I disabled the Real-time Protection in the defender's configuration. As expected the files were not isolated and the attack was successful. However, for the sake of my research I would like to allow the anti-virus still report the alert about the suspicious file even if it does not perform any act agains

Continue reading...
 
Back
Top Bottom