Skip to content

Windows Defender Antivirus #1729

@jamiehynds

Description

@jamiehynds

Description

Microsoft Defender Antivirus, formerly known as Windows Defender, is an antivirus program bundled with Windows 10. Microsoft Defender Antivirus has many features, including substantial security settings for individual users and groups.

Architecture

Similar to PowerShell events, Windows Defender writes events to a Windows Event channel - Windows Defender/Operational. While users can leverage our Custom Windows Event integration to ingest these events, ECS mappings are not applied.

Integration release checklist

This checklist is intended for integrations maintainers to ensure consistency
when creating or updating a Package, Module or Dataset for an Integration.

All changes

  • Change follows the contributing guidelines
  • Supported versions of the monitoring target are documented
  • Supported operating systems are documented (if applicable)
  • Integration or System tests exist
  • Documentation exists
  • Fields follow ECS and naming conventions
  • At least a manual test with ES / Kibana / Agent has been performed.
  • Required Kibana version set to:

New Package

  • Screenshot of the "Add Integration" page on Fleet added

Dashboards changes

  • Dashboards exists
  • Screenshots added or updated
  • Datastream filters added to visualizations

Log dataset changes

  • Pipeline tests exist (if applicable)
  • Generated output for at least 1 log file exists
  • Sample event (sample_event.json) exists

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions