Though the Windows thing was really funny 😂.

  • 0x4E4F@sh.itjust.worksOP
    link
    fedilink
    English
    arrow-up
    1
    ·
    3 months ago

    No, it scans file headers when you do read/write operations on disk. Every AV works this way, except, as I said, Defender is slow AF.

    • uis
      link
      fedilink
      arrow-up
      1
      ·
      3 months ago

      I can’t find talk I watched, but I found github issue it was based on.

      Short version: Defender is triggered not on open, not on read or write, but on CloseHandle.