article thumbnail

Reverse, Reveal, Recover: Windows Defender Quarantine Forensics

Fox IT

The most extensive documentation we could find on the structures of Windows Defender quarantine files was Florian Bauchs’ whitepaper analyzing antivirus software quarantine files , but we also looked at several scripts on GitHub. It makes sense that a function intended for backing up data preserves these alternate data streams as well.