Even though Defender has a lot of fancy defensive features such as tamper protection, it can still be disabled with the following chain of actions: enable SeDebugPrivilege; start the TrustedInstaller ...