Forum Discussion
Microsoft defender is not catching threats before they are put into download folder.
Before I post this, please note that I’m a security researcher trained to investigate malware and other application bugs. my complaint is the following and it's a serious one that should be fixed by Microsoft as soon as possible.
When I downloaded several malicious EXE files, Microsoft Defender didn't block or quarantine them during the download. Instead, Defender only detected them after I actually ran or executed the files. I also noticed that online platforms showed Microsoft Defender detecting the threats, so the files were clearly being recognized as malicious by Defender's engine. Has Microsoft changed the way Defender detects malware? Does it now require a malicious file to be executed before it detects it, similar to how some behavioral detection works in Malwarebytes? Or should Defender still be detecting and blocking known malicious EXE files before they are executed/downloaded because it's not at this current time and this is a clean installed system.
My system is clean, and I even performed a clean installation of Windows. I also used ConfigureDefender with the settings configured to High, and all of the relevant protection settings appeared to be enabled.I'm trying to understand whether this is normal behavior with the current version of Microsoft Defender or if something might be misconfigured on my system. Before, Microsoft Defender would detect and block malicious files while they were being downloaded, before I had a chance to run or execute them. Now, however, it seems like Defender is allowing the files to finish downloading and only detects them after I execute them.
Windows Defender isn't detecting EICAR test files? Mine doesn’t seem to detect them automatically, as shown in my proof. It only detects the file when I right-click it and select “Scan with Microsoft Defender.” Is this normal? It seems pretty crazy that it doesn’t detect the file immediately. it allowed them all to download. It's not even blocking Eicar test files when i bypass edges warning to download it just allows it to download no problem. edge detects it but Microsoft security does not.
Please have Microsoft’s threat team investigate why Windows Defender isn’t detecting malicious files when downloaded through Microsoft Edge. When Edge warns about a malicious or suspicious download and those warnings are bypassed, the files aren’t caught or blocked by Defender and end up being saved to the system. This is extremely dangerous and needs to be replicated to confirm the issue.