
How Critical Start's SOC stopped an attacker from disabling AV protections and quietly creating an admin foothold — before a single payload could deploy.
Download the full case study
Get the complete PDF version of this Tales from the SOC story.
Threat Type: Defense evasion and persistence through manipulation of endpoint protection policies and unauthorized administrative access
Time to Containment: 28 Minutes
This incident involved an attacker attempting to weaken endpoint defenses and establish administrative persistence within a cloud-hosted environment. By modifying antivirus exclusions and applying them across production Azure servers, the attacker aimed to create a blind spot in Microsoft Defender that could enable undetected malicious activity.
Before the attacker could leverage this access to deploy additional payloads or move laterally, Critical Start SOC analysts identified abnormal configuration changes and intervened.
Attack Characteristics: The attacker began by altering antivirus exclusion settings in Microsoft Defender, allowing specific file types such as .exe and wildcard file paths to bypass scanning.
These exclusions were then applied broadly across production Azure servers, effectively weakening endpoint protection controls and enabling potential malware execution without detection.
Shortly after the changes were deployed, the attacker created a new administrative account in the Defender portal, attempting to establish persistence and maintain remote control over security configurations.
This tactic is commonly used to disable or manipulate defenses prior to deploying additional malicious activity.
Initial Vendor Severity: Configuration change alert
SOC Escalation: High priority due to policy manipulation and administrative account creation
SOC analysts detected suspicious Defender configuration changes combined with the creation of a new privileged admin account. This pattern is strongly associated with defense evasion and persistence techniques, prompting immediate escalation and investigation.
Critical Start analysts performed a multi-layer investigation that included:
This rapid investigation confirmed the attacker had successfully weakened defenses and created an administrative foothold.
Modification of AV exclusion settings implemented in Windows Defender console
Virus scanning exclusions for ".exe" and "*.*" applied to all production Azure servers
Critical Start initiated investigation and identified a new admin account created in Defender portal
Critical Start notified customer, disabled the new admin account, and reversed the suspicious settings
The SOC initiated an immediate response to neutralize the threat:
This coordinated response prevented the attacker from using the weakened defenses to deploy malware or expand access.
By rapidly detecting abnormal configuration activity and removing the attacker's administrative access, the SOC prevented defense evasion from turning into a broader compromise.
This swift response restored security controls across the environment, eliminated the attacker's persistence mechanism, and ensured production Azure systems remained protected.
© 2026 Critical Start. All rights reserved.
