@@ -96,50 +96,130 @@ The Windows Defender scan DetectionHistory file consists of:
96
96
97
97
=== Known values
98
98
99
+ The known values consists of multiple sets of values that are separated by
100
+ a value containing the string "Magic.Version:1.2".
101
+
102
+ * set 1, which contains basic information
103
+ * set 2, which contains threat information
104
+ * one of more set 3, which contains information about threat detection resources
105
+
106
+ [yellow-background]*TODO: if information is related to MSFT_MpThreat or MSFT_MpThreatDetection classes?*
107
+
108
+ ==== Known values - set 1
109
+
99
110
[cols="1,1,5",options="header"]
100
111
|===
101
112
| Value index | Value | Description
102
- 3+| _Information related to MSFT_MpThreat class?_
103
113
| 0 | | Threat identifier
104
114
| 1 | | Identifier +
105
115
Contains the GUID corresponding to the file name
106
- | 2 | "Magic.Version:1.2" | [yellow-background]*Unknown (signature and version?)*
107
- | 3 | | Name of the threat that was detected +
116
+ |===
117
+
118
+ ==== Known values - set 2
119
+
120
+ [cols="1,1,5",options="header"]
121
+ |===
122
+ | Value index | Value | Description
123
+ | 0 | "Magic.Version:1.2" | Known values set separator
124
+ | 1 | | Name of the threat that was detected +
108
125
For example: "Virus:DOS/EICAR_Test_File"
109
- | 4 | | [yellow-background]*Unknown* +
126
+ | 2 | | [yellow-background]*Unknown* +
110
127
Seen: 0
111
- | 5 | | [yellow-background]*Unknown* +
128
+ | 3 | | [yellow-background]*Unknown* +
112
129
Seen: 5
113
- | 6 | | Category +
130
+ | 4 | | Category +
114
131
See section: <<category,Category>>
115
- | 7 | | [yellow-background]*Unknown* +
116
- Seen: 0x6e
117
- | 8 | | [yellow-background]*Unknown (Severity?)* +
132
+ | 5 | | [yellow-background]*Unknown* +
133
+ Seen: 49 (last value index 10), 63 (last value index 12), 110 (last value index 13)
134
+ | 6 | | [yellow-background]*Unknown (Severity?)* +
118
135
Seen: 4
136
+ | 7 | | [yellow-background]*Unknown* +
137
+ Seen: 3
138
+ | 8 | | [yellow-background]*Unknown* +
139
+ Seen: 3
119
140
| 9 | | [yellow-background]*Unknown* +
120
141
Seen: 3
121
142
| 10 | | [yellow-background]*Unknown* +
122
143
Seen: 3
144
+ 3+| _Optional values_
123
145
| 11 | | [yellow-background]*Unknown* +
124
- Seen: 3
125
- | 12 | | [yellow-background]*Unknown* +
126
- Seen: 3
127
- | 13 | | [yellow-background]*Unknown* +
128
146
Seen: 2
129
- | 14 | | [yellow-background]*Unknown* +
147
+ | 12 | | [yellow-background]*Unknown* +
130
148
Seen: 6
131
- | 15 | | [yellow-background]*Unknown* +
149
+ | 13 | | [yellow-background]*Unknown* +
132
150
Seen: 1
133
- 3+| _Information related to MSFT_MpThreatDetection class?_
134
- | 16 | "Magic.Version:1.2" | [yellow-background]*Unknown (signature and version?)*
135
- | 17 | "file" | [yellow-background]*Unknown*
136
- | 18 | | [yellow-background]*Unknown (path of file)*
151
+ |===
152
+
153
+ ==== Known values - set 3
154
+
155
+ [cols="1,1,5",options="header"]
156
+ |===
157
+ | Value index | Value | Description
158
+ | 0 | "Magic.Version:1.2" | Known values set separator
159
+ | 1 | | Resource type +
160
+ Seen: "file", "regkey", "regkeyvalue", "startup", "uninstall"
161
+ | 2 | | Resource location +
162
+ Seen: file path, Windows Registry key path
163
+ | 3 | | [yellow-background]*Unknown* +
164
+ Seen: 0, 0x10000001
165
+ | 4 | | Thread data size
166
+ | 5 | | Thread data
167
+ 3+| _Optional values_
168
+ | 6 | | [yellow-background]*Unknown date and time*
169
+ | 7 | | [yellow-background]*Unknown* +
170
+ Seen: 0
171
+ | 8 | | [yellow-background]*Unknown* +
172
+ Seen: 0
173
+ | 9 | | [yellow-background]*Unknown GUID*
174
+ | 10 | | [yellow-background]*Unknown* +
175
+ Seen: 0, 1
176
+ | 11 | | [yellow-background]*Unknown* +
177
+ Seen: 2, 6
178
+ | 12 | | User/System account name
179
+ | 13 | | [yellow-background]*Unknown* +
180
+ Seen: 2, 3
181
+ | 14 | | [yellow-background]*Unknown (parent process?)* +
182
+ Seen: Path of parent process executable, "Unknown"
183
+ | 15 | | [yellow-background]*Unknown* +
184
+ Seen: 2, 3
185
+ | 16 | | [yellow-background]*Unknown* +
186
+ Seen: 0, 1
187
+ | 17 | | [yellow-background]*Unknown* +
188
+ Seen: 0
189
+ | 18 | | [yellow-background]*Unknown date and time*
137
190
| 19 | | [yellow-background]*Unknown* +
138
- Seen: 0x10000001
139
- | 20 | | [yellow-background]*Unknown (threat data size?)*
140
- | 21 | | [yellow-background]*Unknown (threat data?)*
191
+ Seen: 0, 3
192
+ | 20 | | [yellow-background]*Unknown date and time*
193
+ | 21 | | [yellow-background]*Unknown* +
194
+ Seen: 0
195
+ | 22 | | [yellow-background]*Unknown* +
196
+ Seen: 0
197
+ | 23 | | [yellow-background]*Unknown* +
198
+ Seen: 0
199
+ | 24 | | User/System account name
200
+ | 25 | | [yellow-background]*Unknown* +
201
+ Seen: 0
202
+ | 26 | | [yellow-background]*Unknown* +
203
+ Seen: 0
204
+ | 27 | | [yellow-background]*Unknown* +
205
+ Seen: 0
206
+ | 28 | | [yellow-background]*Unknown* +
207
+ Seen: 0
208
+ | 29 | | [yellow-background]*Unknown* +
209
+ Seen: 0
210
+ | 30 | | [yellow-background]*Unknown* +
211
+ Seen: 0
212
+ | 31 | | [yellow-background]*Unknown* +
213
+ Seen: 1
141
214
|===
142
215
216
+ ....
217
+ Possible date and time values:
218
+ InitialDetectionTime
219
+ LastThreatStatusChangeTime
220
+ RemediationTime
221
+ ....
222
+
143
223
=== [[category]]Category
144
224
145
225
[cols="1,1,5",options="header"]
0 commit comments