Forum Discussion

AntonvRooyen1715's avatar
AntonvRooyen1715
Copper Contributor
Jan 19, 2024

Kali ISO download shows as current threat on Virus and Threat protection list

Hi guys,

 

I recently downloaded the KALI Linux ISO. Every time i go to Windows Security is shows 'Threats found...'. On further inspection shows 'Threat found - action needed and I cannot remove it with Defender.

  • LeonPavesic's avatar
    LeonPavesic
    Silver Contributor

    Hi AntonvRooyen1715,

    it's not unusual for Windows Security to raise alerts when scanning a Kali Linux ISO, as Kali Linux is primarily designed for penetration testing and ethical hacking. The tools included in Kali Linux are often flagged due to their potential misuse, even though they are not inherently harmful.

    Downloading the ISO from the official Kali Linux website minimizes the risk of compromise, but it's advisable to verify the file integrity by checking its hash against the one provided on the website.

    If Windows Security detects threats within the ISO file and doesn't remove them, it may be because the threats are embedded in the image. Deleting the ISO file may not resolve the issue, as Windows Security retains a scan history that includes the recorded threats.

    To clear the Windows Defender history:

    1. Navigate to C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service.
    2. Delete all contents within the Service folder.

    This action only clears the threat history, not the actual threats.

    antivirus - Windows Defender found threats in Kali Linux disc image - Information Security Stack Exchange

    WINDOWS DEFENDER IS NOT REMOVING THREATS - Microsoft Community


    Please click Mark as Best Response & Like if my post helped you to solve your issue.
    This will help others to find the correct solution easily. It also closes the item.


    If the post was useful in other ways, please consider giving it Like.


    Kindest regards,


    Leon Pavesic
    (LinkedIn)

    • AntonvRooyen1715's avatar
      AntonvRooyen1715
      Copper Contributor
      Thank you LeonPavesic. The path Navigate to C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service is not a valid path on my system. I have read the other attached threads on the URL you provided and the logic seams sound. I just need to get the path on my Windows 11 Pro device

Resources