Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News Editorials & Other Articles General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

BootinUp

(50,962 posts)
4. Defender does use heuristics according to the MS tech doc
Sat Jan 3, 2026, 08:35 PM
Jan 3
https://learn.microsoft.com/en-us/defender-endpoint/configure-protection-features-microsoft-defender-antivirus

Microsoft Defender Antivirus uses several methods to provide threat protection:

Cloud protection for near-instant detection and blocking of new and emerging threats

Always-on scanning, using file and process behavior monitoring and other heuristics (also known as "real-time protection&quot

Dedicated protection updates based on machine learning, human and automated big-data analysis, and in-depth threat resistance research

https://learn.microsoft.com/en-us/defender-endpoint/configure-real-time-protection-microsoft-defender-antivirus

Always-on protection consists of real-time protection, behavior monitoring, and heuristics to identify malware based on known suspicious and malicious activities. These activities include events, such as processes making unusual changes to existing files, modifying or creating automatic startup registry keys and startup locations (also known as autostart extensibility points, or ASEPs), and other changes to the file system or file structure. Always-on protection is an important part of your antivirus protection and should be enabled.

Recommendations

1 members have recommended this reply (displayed in chronological order):

Latest Discussions»Help & Search»Computer Help and Support»Is Microsoft Defender goo...»Reply #4