I frequently use the tools in Microsoft's OWN sysinternals toolset for performing various operations on my network, and every time I usually have to hit the notification that pops up and "allow" the program before defender squirrels it away to it's vault of the damned never to be seen again. However!!! sysinternals is a walk in the park compared to "NirSoft" NirSoft (https://www.nirsoft.net/) make some absolutely amazing tools, tools that should be in every I.T. engineers bag of tricks when dealing with those folks that forget their passwords and/or routinely screw things up on their windows system, windows defender treats just about every single program in the tool set as malicious. Not only that, but once over it would list all the offending programs in one go, until folks started clicking on "Allow all", so it now lists every one singly and in such rapid succession that you just do not get time to click on the alert, hoist to admin, select "allow" and save, before that entry is "automatically processed" and your moved on to the next alert. It appears also that "Allowing" a file now only stays in place for a limited length of time, so after a while the allowance is lifted and you start the dance all over again. In order for Windows to not destroy my tools collection, I've now started keeping it all on a Linux based SMB share where EVERYTHING is set to read only. Defender goes absolutely nut's when I open that folder now.