Windows Security Center API Guard & Antivirus Registration Analyzer

TTP-WSC-ANALYSIS-STATION
DEFENDER: PASSIVE (SUPPRESSED)
SECURITY PROVIDERS: 1 ACTIVE
Provider Registration Controls WSC-API v2
Simulation Presets
Windows Defender Operational Mode
PASSIVE MODE (TAMPERED)
Tamper Protection State
Bypassed via WSC API
1. Active RTP
MsMpEng Running
2. WSC Event
Provider Registered
3. Passive Mode
Defender Quenched
4. Threat Posture
Zero Real Scanning
Security Impact: Windows Defender automatically cedes real-time scanning control when a registered 3rd-party provider asserts active RTP status in WSC, circumventing Tamper Protection without triggering typical service termination alerts.
Active Provider Security Center Telemetry SIGNATURE REJECTED
Registered Provider Name
PhantomGuard AV
Provider Instance GUID
{F2B83120-4E9A-4B7C-9182-3A2B1C9D8E7F}
Registration Method
User-Mode API Injection
Authenticode Trust Verification
FAIL: Self-Signed / Untrusted Root
WSC Product State Hex Mask
0x00041000 (RTP Enabled, Defs Current)
Defender Engine Fallback
Disabled (Suppress Antivirus Conflict)
DFIR Windows Security Center Telemetry Log Event Log & API Monitor
Detection Engineering & DFIR Rules
title: Suspicious WSC Antivirus Provider Registration id: wsc-fake-av-passive-mode status: production description: Detects unauthorized registration of third-party security products in Windows Security Center designed to disable Defender RTP. logsource: product: windows service: security-center detection: selection_provider: EventID: 1151 filter_known_vendors: ProviderGuid|contains: - '{CrowdStrike-ELAM-Prod}' - '{SentinelOne-TrueRTP}' condition: selection_provider and not filter_known_vendors falsepositives: - Legitimate custom internal antivirus enterprise deployments level: high
Defense Hardening Checklist
AUDIT
Monitor SecurityCenter2 Namespace Changes
Alert on WMI `__InstanceCreationEvent` in `root\SecurityCenter2`.
ENFORCE
Early Launch Anti-Malware (ELAM) Signing
Ensure only Microsoft WHQL signed drivers register as AV.
HARDEN
Force Defender Periodic Scanning (AllowPassiveScan)
Maintain background cloud heuristics even in secondary mode.
INGEST
Forward Windows Event ID 1151 to SIEM
Baseline known enterprise AV GUIDs to flag outliers immediately.
Enjoy this tool? Build your own with Super