w
Jan. 20, 2022, midnight |

SANS Blog www.sans.org

DHParser is an excellent way to gather more complete information on the nature of threats picked up by Windows’ native AV software. Hopefully, the brief introduction to the DetectionHistory artifact has inspired you to dig deeper into what data Windows Defender’s logs can offer to DFIR professionals.

defender history protection windows windows defender

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Advisory Red Consultant

@ Security Risk Advisors | Philadelphia, Pennsylvania, United States

Cyber Business Transformation Change Analyst

@ National Grid | Warwick, GB, CV34 6DA

Cyber Security Analyst

@ Ford Motor Company | Mexico City, MEX, Mexico

Associate Administrator, Cyber Security Governance (Fort Myers)

@ Millennium Physician Group | Fort Myers, FL, United States

Embedded GSOC Lead Operator, Events

@ Sibylline Ltd | Seattle, WA, United States