logo

Reverse, Reveal, Recover: Windows Defender Quarantine Forensics

ID: ef0a057e-2ce3-5601-ad35-f4453b53fb07

STIX ID: report--ef0a057e-2ce3-5601-ad35-f4453b53fb07

Feed Name: Fox-IT blog

Date Published: 2023-12-14

Date Updated: 2026-04-27

...
...

This report documents reverse-engineering of Windows Defender's quarantine format (mpengine.dll) to reveal undocumented metadata and structures (QuarantineEntry, QuarantineEntryResource, QuarantineEntryResourceField, WIN32_STREAM_ID handling). The authors show how to decrypt and parse the three RC4-encrypted sections of QuarantineEntry files, recover quarantined file contents and NTFS alternate data streams (e.g., Zone.Identifier and security descriptors), and implement the parser as a plugin for the Dissect DFIR framework using dissect.cstruct to aid forensic recovery.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.