See what Defender is doing. Keep it doing it.
Defender Status is a portable Windows app that shows your protection status, signature age, exclusions and detection history in one clear screen โ and cannot switch any of it off.
Portable ยท ~60 MB ยท No installer ยท No telemetry ยท MIT licensed
Everything worth knowing, on one screen
No dashboards to learn and nothing to configure. Open it, read it, close it.
Posture verdict
Every protection component rolls up into a single headline, so you know in a second whether anything needs a look.
Protection components
Real-time protection, behaviour monitoring, IOAV, network inspection, cloud-delivered protection, tamper protection and more.
Signatures & engine
Signature version and age with a clear warning when they have not updated in over a week.
Detection history
What Defender found, how severe it was, what it did about it, and where the file lived.
Configured exclusions
Every folder, process and file type Defender is told to skip. The place surprises hide.
Markdown reports
Export the whole picture to your Documents folder, or copy it to the clipboard for a support ticket.
Verified auto-update
Pulls new builds from GitHub Releases and checks the SHA-256 before anything is installed.
Firewall profiles
Domain, private and public firewall status at a glance.
Truly portable
One executable. No installer, no service, no registry keys, no leftover files.
Why it does not disable anything
Disablers are easy to find and easy to regret. Defender Status takes the other road.
| Capability | Defender Status | Typical disabler |
|---|---|---|
| Read protection status, signatures, scans | Yes | Sometimes |
| List configured exclusions | Yes | Rarely |
| Cannot turn protection off | Yes โ by design | No |
| Needs administrator to run | Only for the exclusions list | Almost always |
| Portable, no installer | Yes | Sometimes |
| Verified self-update | Yes, SHA-256 checked | Usually none |
Frequently asked
Does this disable Windows Defender?
No. It never has and it is not designed to. The application only calls the read side of the Defender PowerShell module. It cannot turn real-time protection on or off, change exclusions, or modify firewall rules. If you need to change Defender configuration, use Windows Security or your organisation's device management tooling.
Why does it ask for administrator rights?
It does not, unless you want to read the exclusions list. Windows only exposes configured exclusions to elevated processes. Without elevation the app shows the read-only panels that do not need it and marks the exclusions as unavailable rather than guessing.
Is it really portable?
Yes. It is a single self-contained executable. There is no installer and nothing is written to the registry. Settings and the log live under %LOCALAPPDATA%\DefenderStatus, and deleting that folder removes every trace.
Why does SmartScreen warn me?
Because new, unsigned applications always get a warning. You can verify the download with the published SHA-256 before running it, or build it yourself from source with a single dotnet publish command.
Does it collect any data?
No. There is no telemetry and no analytics. The only network request is the update check against the public GitHub Releases API for this repository, and it can be turned off in Settings.
How does the auto-update work?
It asks GitHub for the latest release, downloads the attached executable if it is newer, verifies its SHA-256 against the published checksum, and then swaps the binary only when you press Install and restart. A checksum mismatch deletes the download and installs nothing.
Look before you touch
Download Defender Status, read the situation, and let Defender keep doing its job.
Download for Windows