Hackers can now disable Windows Defender using a new tool called Defendnot created by a security researcher named es3n1n.
Defendnot exploits an undocumented Windows Security Center API to trick the OS into thinking a fake antivirus program is running, causing Windows Defender to shut down.
A previous similar tool by es3n1n was removed due to copyright infringement, prompting the creation of Defendnot with a new approach and an autorun feature.
Microsoft Defender is now able to detect and isolate Defendnot as a threat, ensuring protection against this form of attack.