Read more about this at https://x.com/VakninHai/status/1796628601535652289
A quote from that post
Admins can set and read exclusion paths in Microsoft Defender, but did you know low-privileged users can view Event 5007 and see these paths too?
The code in this repo comes from https://x.com/I_Am_Jakoby/status/1797670291025637645
There is also a Rust version available at https://github.com/BlackSnufkin/Rusty-Playground/tree/main/DefExclusions
All credit for this goes to the three people mentioned above.
Adding Invoke-DumpDefenderConfig.ps1.
Found the creator of this file: https://github.com/BlackSnufkin/Invoke-DumpMDEConfig