Features of reading the Microsoft Defender quarantine
Latest materials
- Out-of-bounds write in ntfs!PageUpdateAnalysis
A heap buffer overflow vulnerability exists in the ntfs!PageUpdateAnalysis function of the Microsoft Windows NTFS driver.…
- This is Siemens...
Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar.…
- Anti-antivirus
Recently, we came across an APK with an intriguing and trust-inspiring name: «Антивирус ФСБ.apk». After installing…
- We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert…
- Recovering EVTX records: carving methods
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a…
🧐 Peculiarities of Reading the Microsoft Defender Quarantine
And those who want to and can, do this, among other things, using the script defender-dump.py. In the script’s description, the authors honestly stated that they work with a single type of records — file. However, upon closer examination, it turns out that there are somewhat more record types.
Decoding the files from the folder according to the scheme described in the script:
C:\ProgramData\Microsoft\Windows Defender\Quarantine\Entries
At minimum, one can encounter records of the types regkey, runkey, regkeyvalue, and service, and a single detection event may correspond to several records simultaneously (which corresponds to entries in the EVTX channel Microsoft-Windows-Windows Defender/Operational with code 1117, where a single event features quite a few paths).
In most cases, everything is fairly transparent — detected records having a type other than file correspond to registry fragments and sometimes allow identifying malware persistence:
HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSI
HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\netcat runkey 3F005C0043003A005C00770069006E0064006F00
C:\Windows\System32\nc.exe file 7305273EFC20E59A96E8AAFA2068ABD47693F773
Quarantine files are described by corresponding IDs and are located in the folders:
C:\ProgramData\Microsoft\Windows Defender\Quarantine\ResourceData\<First byte of ID>\<ID>
Such files almost always correspond to records of the file type, and the quarantine contents can be extracted according to the scheme described in the aforementioned script: after RC4 decryption, two offsets are read from the structure, and the buffer fragment can safely be saved as a trophy.
However, there are exceptions to every rule — upon closer examination, it turns out that, in particular, for records of the service type:
1️⃣ The ID begins with the “magic word” 0x0000000014000A40, after detecting which one can find the real ID.
2️⃣ The quarantine decoding scheme stops working — the value of the parameter determining the maximum size of the extracted fragment often turns out to be a number many times greater than the size of the buffer itself.
In such cases, one should ignore the read offsets and consider the entire decoded buffer as the extracted quarantine, which has the magic number REGF and turns out to be a registry fragment. Parsing the fragment, as a rule, is no longer difficult.
Latest materials
- Out-of-bounds write in ntfs!PageUpdateAnalysis
A heap buffer overflow vulnerability exists in the ntfs!PageUpdateAnalysis function of the Microsoft Windows NTFS driver.…
- This is Siemens...
Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar.…
- Anti-antivirus
Recently, we came across an APK with an intriguing and trust-inspiring name: «Антивирус ФСБ.apk». After installing…
- We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert…
- Recovering EVTX records: carving methods
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a…





