WithSecureLabs / chainsaw

Rapidly Search and Hunt through Windows Forensic Artefacts
GNU General Public License v3.0
2.7k stars 242 forks source link

Update Windows Defender rule to filter for key EventIDs #153

Closed reece394 closed 8 months ago

reece394 commented 8 months ago

This updates the windows_defender.yml rule file to filter for EventIDs instead of saving all of the EventIDs to the spreadsheet. This should cut down on the noise of the resulting antivirus file. Tested on several engagements and works well.