logo

Windows Defender Quarantine Forensics Guide

ID: e4d9eb90-52da-5034-8614-08d5bd9bb1bc

STIX ID: report--e4d9eb90-52da-5034-8614-08d5bd9bb1bc

Feed Name: NCC Research

Date Published: 2026-05-14

Date Updated: 2026-08-01

...
...

This report presents a technical analysis of Windows Defender quarantine internals: reverse engineering mpengine.dll to uncover previously undocumented QuarantineEntry and QuarantineEntryResourceField structures, demonstrating how quarantined files and metadata (including timestamps, NTFS alternate streams like Zone.Identifier, and security descriptors) are stored and RC4-encrypted, and providing a Dissect framework plugin that recovers these artifacts for DFIR purposes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.