The archive

#Windows Security

Practical IT guides, comparisons, explainers and news — curated by practitioners.

12articles
38Topics
~10Avg min read
209Total views

12 articles · Curated and written by practitioners

FeaturedSquare Microsoft news cover warning of a known Defender Antivirus false alert that incorrectly says protection is turned off even though the antivirus continues running normally, with a fix still pending.
Microsoft Defender

Microsoft Tells Users to Ignore False 'Antivirus Is Turned Off' Alerts

Microsoft has confirmed a known issue in which recent Microsoft Defender Antivirus updates trigger false "Microsoft Defender Antivirus is turned off" alerts in the Windows Security app, even though the antivirus is running normally. The bug affects all supported Windows client and server versions, including Windows 11 26H1 and Windows Server 2025, and a fix is still pending.

Sep 2, 2026, 9:02 PM 6 min
11
EEmanuel De Almeida
Read article
Sleepwalker, a stealthy Windows backdoor that hides in memory as a fake dpapi.dll.
Windows Security

Sleepwalker: New Windows Backdoor Hides in Memory Until a 'Magic Packet' Wakes It

Researcher Dominik Reichel has detailed Sleepwalker, a previously unseen passive Windows backdoor that hides in memory as a fake dpapi.dll and stays dormant until it receives a specially crafted network packet, then decrypts a 23-instruction command set over TCP, UDP, ICMP, SMB pipes or VMware VMCI.

Aug 26, 2026, 8:37 PM 6 min
22
EEmanuel De Almeida
Cruciferra Crypter cybersecurity graphic explaining how a $450-per-month malware service conceals remote access trojans from.
Malware

Cruciferra Crypter: How a $450-a-Month Service Hides RATs From EDR

Proofpoint has published an analysis of Cruciferra, a crypter service sold since autumn 2025 that combines BYOVD driver abuse, API unhooking and a modified Process Ghosting routine to deliver commodity RATs and infostealers through phishing.

Jul 27, 2026, 10:26 PM 10 min
6
EEmanuel De Almeida
How to enable Core Isolation Memory Integrity in Windows 11 through Windows Security, with device security, restart.
Windows 11

How to Enable Core Isolation Memory Integrity in Windows 11

Learn how to enable Memory Integrity (HVCI) in Windows 11 via Windows Security, Group Policy, Registry, or Intune. Includes troubleshooting for incompatible drivers and BIOS virtualization requirements.

Jul 23, 2026, 9:07 PM 8 min
23
EEmanuel De Almeida
Mshta.exe as a legitimate Windows LOLBin that runs HTA files but can be abused by attackers.
mshta.exe

What Is mshta.exe? Windows LOLBin Security Explainer

mshta.exe is a Windows binary for running HTA files. Per MITRE ATT&CK T1218.005, attackers abuse it as a LOLBin to execute malicious VBScript/JScript, bypass AppLocker, and proxy payload execution. Covers detection, blocking, and defense strategies.

Jul 23, 2026, 4:42 PM 8 min
20
EEmanuel De Almeida
Windows Event ID 5061 for a cryptographic operation, with Event Viewer, encryption keys, certificates, algorithms.
Windows Security

Event ID 5061: Cryptographic Operation Explained

Event ID 5061 is a Windows security audit event that logs cryptographic operations performed through a Key Storage Provider. This explainer covers what triggers it, how to read its fields, the common 0x80090016 failure, and when it signals a real security concern.

Jul 20, 2026, 1:56 AM 11 min
13
EEmanuel De Almeida
Windows Event ID 4625 for failed logon attempts, with Event Viewer, account errors, brute-force detection.
Event ID 4625

What Is Windows Event ID 4625? Failed Logon Monitoring and Attack Detection Explained

Windows Event ID 4625 logs every failed logon attempt. This explainer covers Sub Status codes, Logon Types, brute-force detection patterns, audit policy setup, and PowerShell analysis techniques.

Jul 19, 2026, 12:58 AM 12 min
33
EEmanuel De Almeida
Windows Event ID 4728 for a user added to a security-enabled global group, with Active Directory, Event Viewer, auditing.
Active Directory

What Is Windows Event ID 4728? Active Directory Group Membership Auditing Explained

Windows Event ID 4728 logs every time a member is added to a security-enabled global group in Active Directory. This explainer covers what the event means, how it works, why it matters for security teams, and how to monitor it effectively.

Jul 18, 2026, 9:43 PM 12 min
5
EEmanuel De Almeida
Microsoft Defender patching the RoguePlanet zero-day vulnerability, CVE-2026-50656, through a security engine update.
Microsoft Defender

Microsoft Patches "RoguePlanet" Defender Zero-Day (CVE-2026-50656) via Engine Update

Microsoft has released Malware Protection Engine 1.1.26060.3008 to fix "RoguePlanet" (CVE-2026-50656), a Microsoft Defender race-condition zero-day that a researcher using the "Nightmare Eclipse" handle said could grant SYSTEM privileges on fully patched Windows 10 and 11 devices.

Jul 11, 2026, 3:19 AM 5 min
5
EEmanuel De Almeida
How to disable Microsoft Defender Antivirus on Windows Server 2019 and 2022 using Server Manager, Group Policy, Registry.
Windows Server

How to Disable Windows Defender on Windows Server 2019 and 2022

Step-by-step guide to disabling or uninstalling Microsoft Defender Antivirus on Windows Server 2019 and 2022 using PowerShell, Group Policy, the registry, or Server Manager - safely and with a replacement AV.

Jul 6, 2026, 6:50 AM 19 min
44 Trending
EEmanuel De Almeida
How to fix Remote Desktop authentication error 0x80004005 on Windows 10, Windows 11, and Windows Server, with NLA, CredSSP.
Remote Desktop

Fix Remote Desktop Authentication Error 0x80004005 on Windows 10, 11, and Windows Server

Getting "An authentication error has occurred (Code: 0x80004005)" when connecting with Remote Desktop? Fix the NLA and CredSSP causes with the right credentials, updates, and .rdp settings.

Jul 5, 2026, 3:37 PM 15 min
7
EEmanuel De Almeida
Windows 10 Extended Security Updates enrollment, with a secured laptop, update progress, eligibility checks, purchase.
Windows 10

How to Activate Windows 10 ESU (Extended Security Updates): Complete Enrollment Guide

Windows 10 hit end of support on October 14, 2025. This guide walks through every ESU activation path: consumer enrollment, commercial MAK activation with slmgr, and Intune deployment, so your devices keep getting security updates.

May 12, 2026, 1:58 AM 13 min
20 1
EEmanuel De Almeida