Check defender status#
If RealTimeProtectionEnabled is set to True, then it is on
Get-MpComputerStatussc query windefendDisable defender (need admin)#
Set-MpPreference -DisableRealtimeMonitoring $trueCheck exclusion (no priv)#
Get-WinEvent -LogName "Microsoft-Windows-Windows Defender/Operational" -FilterXPath "*[System[(EventID=5007)]]" | Where-Object { $_.Message -like "*Exclusion*"} | Select-Object Message | FL