Linux is a wasteland of terrible security practices that sysadmins excuse as "acceptable" for their own workstations and servers because they think that locking down SSH is sufficient defense against e.g. malicious infections or "curl | bash".
I'm sorry that Defender has harmed you, but that's no excuse to recommend others disable automated Defender scans on some sort of schedule.