Security

The security model

Defender Status is deliberately narrow. This page states exactly what it can do, what it cannot, and why that line is drawn where it is.

What it does

What it cannot do

There is no hidden switch for any of these. The application contains no Set-MpPreference, no registry writes to security keys, no service control calls, and no policy edits.

Why read-only is the right default

Tools that disable Defender are trivial to write and dangerous to run. Real-time protection is the layer that stops a malicious file the moment it is opened; turning it off for "just a minute" is how a great many infections begin, and the plan to switch it back rarely survives the next reboot. The honest observation is that most people reaching for a disabler wanted visibility — they wanted to know why something was being blocked or what had been flagged. Defender Status provides exactly that, and leaves the protection intact.

If you have a genuine, authorised need to reconfigure Defender — for example in a managed environment with its own control plane — Windows Security and your device-management tooling are the correct places to make those changes, because they record who changed what and why.

Handling of a downloaded update

  1. The new build is downloaded to a temporary folder.
  2. If the release publishes a .sha256 asset, the downloaded file's hash is computed and compared. A mismatch deletes the file and aborts.
  3. Nothing is installed until you press Install and restart.
  4. The replacement happens after the current process exits, via a short-lived helper that moves the new binary into place and relaunches it.

When a release has no published checksum, the app says so in the activity log rather than pretending verification happened.

Reporting a problem

Security-relevant issues should be sent privately rather than opened as a public issue. Use the private report form on this site — it files a GitHub security advisory that only the maintainers can read, and needs no account — or open the advisory form directly on GitHub. General bugs and feature requests are welcome on the issue tracker.