-
Notifications
You must be signed in to change notification settings - Fork 562
Windows Defender Antivirus #1729
Copy link
Copy link
Closed
Labels
Category: EDR/EPP/XDRNew IntegrationIssue or pull request for creating a new integration package.Issue or pull request for creating a new integration package.Team:Security-Windows PlatformSecurity Windows Platform team [elastic/sec-windows-platform]Security Windows Platform team [elastic/sec-windows-platform]
Metadata
Metadata
Assignees
Labels
Category: EDR/EPP/XDRNew IntegrationIssue or pull request for creating a new integration package.Issue or pull request for creating a new integration package.Team:Security-Windows PlatformSecurity Windows Platform team [elastic/sec-windows-platform]Security Windows Platform team [elastic/sec-windows-platform]
Type
Fields
Give feedbackNo fields configured for issues without a type.
Description
Microsoft Defender Antivirus, formerly known as Windows Defender, is an antivirus program bundled with Windows 10. Microsoft Defender Antivirus has many features, including substantial security settings for individual users and groups.
Architecture
Similar to PowerShell events, Windows Defender writes events to a Windows Event channel - Windows Defender/Operational. While users can leverage our Custom Windows Event integration to ingest these events, ECS mappings are not applied.
Integration release checklist
This checklist is intended for integrations maintainers to ensure consistency
when creating or updating a Package, Module or Dataset for an Integration.
All changes
New Package
Dashboards changes
Log dataset changes
sample_event.json) exists