StepSecurity's Harden Runner detected an unexpected Microsoft Defender installation on GitHub-hosted Ubuntu runners starting July 15, 2025. The wdavdaemon process was making anomalous outbound calls to Microsoft endpoints, which Harden Runner flagged within hours by comparing against established workflow baselines. GitHub
Table of contents
IntroductionThe Discovery: Anomalous Network Calls Raise Red FlagsGitHub's Response: Confirming the Unintentional InstallationHow Harden Runner Detected the AnomalyCommunity Tier: Network VisibilityEnterprise Tier: Deep Process IntelligenceThe Importance of Runtime Security in CI/CDProtecting Your Pipelines with Harden RunnerStart Monitoring in 60 SecondsConclusionSort: