Windows Defender

  • Defender can be a pain, but generally bypasses are abundant. This page is focused on enumeration not bypasses.

  • https://learn.microsoft.com/en-us/powershell/module/defender/

Defender Enumeration with Powershell

Get-MpComputerStatus    #See the status of Defender 
Get-MpPreference        #See current Defender preferences
Add-MpPreference        #Change Defender Settings
Get-MpThreat            #See threat history for computer
Get-MpThreatCatalog     #Show any known threats
Get-MpThreatDetection   #Show all history for any detected threats
Remove-MpThreat         #Remove an active threat
Remove-MpPreference     #Create exclusion and default behavior 
Start-MpScan            #Start Defender Scan
Update-MpSignature      #Signature updates
Set-MpPreference        #Configures scans and updates     

Processes

tasklist /v 
  • look for:

MsMpEng.exe
MpCmdRun.exe

File System artifacts

  • download below files

Registry

Enable Disable RealtimeProtection Powershell

  • Turn On Real-time Protection

  • Turn Off Real-time Protection

See most recent threat

Status Details

Threat History

Last updated