Can you add a reference to your post? https://labs.f-secure.com/blog/bypassing-windows-defender-runtime-scanning/