Windows Defender Quarantine Forensics Guide
ID: e4d9eb90-52da-5034-8614-08d5bd9bb1bc
STIX ID: report--e4d9eb90-52da-5034-8614-08d5bd9bb1bc
Feed Name: NCC Research
This report presents a technical analysis of Windows Defender quarantine internals: reverse engineering mpengine.dll to uncover previously undocumented QuarantineEntry and QuarantineEntryResourceField structures, demonstrating how quarantined files and metadata (including timestamps, NTFS alternate streams like Zone.Identifier, and security descriptors) are stored and RC4-encrypted, and providing a Dissect framework plugin that recovers these artifacts for DFIR purposes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
