DFIRKuiper / Kuiper

Digital Forensics Investigation Platform
736 stars 110 forks source link

Defender Detection History Parser #84

Closed nyrm-f closed 1 year ago

nyrm-f commented 1 year ago

Discribe the parser Parser for windows detection history, example files stored here ProgramData\Microsoft\Windows Defender\Scans\History\Service\DetectionHistory\

https://github.com/jklepsercyber/defender-detectionhistory-parser

Found the above parser and thought it would be good to add to Kuiper if there is not a parser!

salehmuhaysin commented 1 year ago

hello the parser added by @KnorahSa

https://github.com/DFIRKuiper/Kuiper/pull/91