Port 22

Uncovering Windows Defender Real-time Protection History with DHParser

DHParser is an excellent way to gather more complete information on the nature of threats picked up by Windows native AV software. Hopefully, the brief introduction to the DetectionHistory artifact has inspired you to dig deeper into what data Windows Defenders logs can offer to DFIR professionals.