-
Notifications
You must be signed in to change notification settings - Fork 467
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Windows Defender Antivirus #1729
Comments
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
Hi! We just realized that we haven't looked into this issue in a while. We're sorry! We're labeling this issue as |
+1 |
Hi! We just realized that we haven't looked into this issue in a while. We're sorry! We're labeling this issue as |
This integration will still be relevant and useful today. This will also help with: #4564 |
Phase 1 complete with initial data stream created as beta. |
Description
Microsoft Defender Antivirus, formerly known as Windows Defender, is an antivirus program bundled with Windows 10. Microsoft Defender Antivirus has many features, including substantial security settings for individual users and groups.
Architecture
Similar to PowerShell events, Windows Defender writes events to a Windows Event channel - Windows Defender/Operational. While users can leverage our Custom Windows Event integration to ingest these events, ECS mappings are not applied.
Integration release checklist
This checklist is intended for integrations maintainers to ensure consistency
when creating or updating a Package, Module or Dataset for an Integration.
All changes
New Package
Dashboards changes
Log dataset changes
sample_event.json
) existsThe text was updated successfully, but these errors were encountered: