Reverse, Reveal, Recover: Windows Defender Quarantine Forensics
Fox IT
DECEMBER 13, 2023
Rather than just presenting our results, we’ve structured this blog to also describe the process to how we got there. This QuarantineEntry is RC4-encrypted and saved to disk in the /ProgramData/Microsoft/Windows Defender/Quarantine/Entries folder. We noted earlier that the QuarantineEntry contains three RC4-encrypted chunks.
Let's personalize your content