The security model
Defender Status is deliberately narrow. This page states exactly what it can do, what it cannot, and why that line is drawn where it is.
What it does
- Reads Microsoft Defender state through the official PowerShell module.
- Reads firewall profile status through
Get-NetFirewallProfile. - Writes a Markdown report or copies one to the clipboard when you ask.
- Checks the GitHub Releases API for a newer build of itself.
- Installs a newer build only after SHA-256 verification and your explicit confirmation.
What it cannot do
- Turn real-time protection, behaviour monitoring or any other component on or off.
- Add, change or remove exclusions.
- Change firewall rules.
- Modify Defender preferences or policy.
- Stop, disable or unregister any Windows service.
- Collect telemetry or contact any endpoint other than GitHub for updates.
There is no hidden switch for any of these. The application contains no Set-MpPreference, no registry writes to security keys, no service control calls, and no policy edits.
Why read-only is the right default
Tools that disable Defender are trivial to write and dangerous to run. Real-time protection is the layer that stops a malicious file the moment it is opened; turning it off for "just a minute" is how a great many infections begin, and the plan to switch it back rarely survives the next reboot. The honest observation is that most people reaching for a disabler wanted visibility — they wanted to know why something was being blocked or what had been flagged. Defender Status provides exactly that, and leaves the protection intact.
If you have a genuine, authorised need to reconfigure Defender — for example in a managed environment with its own control plane — Windows Security and your device-management tooling are the correct places to make those changes, because they record who changed what and why.
Handling of a downloaded update
- The new build is downloaded to a temporary folder.
- If the release publishes a
.sha256asset, the downloaded file's hash is computed and compared. A mismatch deletes the file and aborts. - Nothing is installed until you press Install and restart.
- The replacement happens after the current process exits, via a short-lived helper that moves the new binary into place and relaunches it.
When a release has no published checksum, the app says so in the activity log rather than pretending verification happened.
Reporting a problem
Security-relevant issues should be sent privately rather than opened as a public issue. Use the private report form on this site — it files a GitHub security advisory that only the maintainers can read, and needs no account — or open the advisory form directly on GitHub. General bugs and feature requests are welcome on the issue tracker.