Reverse, Reveal, Recover: Windows Defender Quarantine Forensics
ID: ef0a057e-2ce3-5601-ad35-f4453b53fb07
STIX ID: report--ef0a057e-2ce3-5601-ad35-f4453b53fb07
Feed Name: Fox-IT blog
This report documents reverse-engineering of Windows Defender's quarantine format (mpengine.dll) to reveal undocumented metadata and structures (QuarantineEntry, QuarantineEntryResource, QuarantineEntryResourceField, WIN32_STREAM_ID handling). The authors show how to decrypt and parse the three RC4-encrypted sections of QuarantineEntry files, recover quarantined file contents and NTFS alternate data streams (e.g., Zone.Identifier and security descriptors), and implement the parser as a plugin for the Dissect DFIR framework using dissect.cstruct to aid forensic recovery.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
