Remove 2022 Remove Blog Remove Data preservation Remove Encryption
article thumbnail

Reverse, Reveal, Recover: Windows Defender Quarantine Forensics

Fox IT

Rather than just presenting our results, we’ve structured this blog to also describe the process to how we got there. This QuarantineEntry is RC4-encrypted and saved to disk in the /ProgramData/Microsoft/Windows Defender/Quarantine/Entries folder. Therefore, we ignore the Resource file for the remainder of this blog.