Windows Defender can be set as default-deny

Available on Win 10 FCU, by either group policy or registry editing (home users):

For more info, read this: Defender Policy CSP - Windows Client Management | Microsoft Learn

Possible options are:
  • (0x0) Default windows defender blocking level
  • (0x2) High blocking level - aggressively block unknowns while optimizing client performance (greater chance of false positives)
  • (0x4) High+ blocking level – aggressively block unknowns and apply additional protection measures (may impact client performance)
  • (0x6) Zero tolerance blocking level – block all unknown executables