Remove 2022 Remove Blog Remove Data preservation Remove Engineering
article thumbnail

Reverse, Reveal, Recover: Windows Defender Quarantine Forensics

Fox IT

Reverse engineering mpengine.dll resulted in finding previously undocumented metadata in the Windows Defender quarantine folder that can be used for digital forensics and incident response. Rather than just presenting our results, we’ve structured this blog to also describe the process to how we got there.