article thumbnail

Reverse, Reveal, Recover: Windows Defender Quarantine Forensics

Fox IT

Rather than just presenting our results, we’ve structured this blog to also describe the process to how we got there. This QuarantineEntry is RC4-encrypted and saved to disk in the /ProgramData/Microsoft/Windows Defender/Quarantine/Entries folder. We noted earlier that the QuarantineEntry contains three RC4-encrypted chunks.