Skip to main content
Warning
This app is archived. App archiving documentation
Microsoft Defender AntiVirus - Technical Add-on app icon

Microsoft Defender AntiVirus - Technical Add-on

This extension for Splunk® is a rewrite of the Add-on already created by pdoconnell (TA-microsoft-windefender) that we adapt to our needs and requirements.Built by Michael from NEXTPART Security Intelligence
splunk product badge

Default Version 0.4.3

August 7, 2023

Compatibility

Splunk Enterprise

Platform Version: 9.4, 9.3, 9.2, 9.1, 9.0

CIM Version: 5.x, 4.x

Rating
5
(1)

Log in to rate this app

Support
Archived Add-on
Ranking

#47 in Endpoint

This extension for Splunk® is a rewrite of the Add-on already created by pdoconnell (TA-microsoft-windefender) that we adapt to our needs and requirements. This add-on is intended as a complement to the Splunk Add-on for Microsoft Windows, which also manages the basic operations of the field extraction from the xml or raw events. If you have installed that add-on you can also use this one to extract more information and present it according to CIM. Code is hosted on Github: https://github.com/nextpart/Defender_TA_nxtp