Microsoft Defender Antivirus Content Pack

The following content pack is available for use with a Graylog Illuminate license and Graylog Enterprise or Graylog Security. Contact sales to learn more about obtaining Illuminate.

Microsoft Defender Antivirus is an anti-malware client service built into supported Windows desktop and server platforms. This technology pack parses, normalizes, and enriches Defender Antivirus events from the Windows Defender Operational log to support detection, response, and operational visibility.

Supported Version(s)

  • Windows 10 and 11 (client)

  • Windows Server 2016 and later

Requirements

  • Windows host with Microsoft Defender Antivirus enabled

  • Graylog 6.0+ with a valid Enterprise license

Stream Configuration

This technology pack includes 1 stream:

  • "Illuminate:Windows Event Log Messages"

Hint: If this stream does not exist prior to the activation of this pack then it is created and configured to route messages to this stream and the associated index set. There should not be any stream rules configured for this stream.

Index Set Configuration

This technology pack includes 1 index set definition:

  • "Windows Event Log Messages"

Hint: If this index set is already defined, then nothing is changed. If this index set does not exist, then it is created with retention settings of a daily rotation and 90 days of retention. These settings can be adjusted as required after installation.

Log Collection

Microsoft Defender Antivirus events are collected from the Microsoft-Windows-Windows Defender/Operational channel of the Windows Event Log. The pack identifies messages delivered through Winlogbeat or NXLog and routes them into the Windows Event Log processing pipeline.

  • Winlogbeat (Graylog Sidecar)

  • NXLog

Log Format Examples

Malware Detection (Event 1116)

{"_winlogbeat_event_created":"2021-09-11T02:06:04.307Z","_winlogbeat_winlog_opcode":"Info","_winlogbeat_agent_id":"897a9958-4efc-4d8d-b5d6-e6649cdd709d","_winlogbeat_ecs_version":"1.5.0","_winlogbeat_event_code":1116,"_winlogbeat_tags":["windows"],"_winlogbeat_winlog_user_identifier":"S-1-5-18","_winlogbeat_winlog_user_type":"User","_winlogbeat_winlog_event_data_State":"1","_winlogbeat_winlog_activity_id":"{F47D9D6A-EB84-4FB5-B4AD-E86083737A24}","_winlogbeat_@timestamp":"2021-09-11T02:06:02.560Z","_winlogbeat_agent_version":"7.9.0","_winlogbeat_agent_ephemeral_id":"bb12ae77-ca9b-446f-a6ea-a8ac5a67e4b7","_winlogbeat_@metadata_version":"7.9.0","_winlogbeat_winlog_record_id":16681,"_winlogbeat_agent_hostname":"JUMPBOX","_winlogbeat_log_level":"warning","_winlogbeat_@metadata_type":"_doc","_winlogbeat_@metadata_beat":"winlogbeat","_winlogbeat_event_provider":"Microsoft-Windows-Windows Defender","_beats_type":"winlogbeat","_winlogbeat_winlog_user_domain":"NT AUTHORITY","_winlogbeat_agent_name":"JUMPBOX","_winlogbeat_winlog_event_id":1116,"_winlogbeat_winlog_event_data_Path":"file:_C:\\Users\\Administrator\\Downloads\\26de80e3bbbe1f053da4131ca7a405644b7443356ec97d48517f1ab86d5f1ca5","_winlogbeat_host_name":"JUMPBOX","_winlogbeat_winlog_channel":"Microsoft-Windows-Windows Defender/Operational","_winlogbeat_winlog_user_name":"SYSTEM","_winlogbeat_winlog_computer_name":"JUMPBOX","_winlogbeat_event_kind":"event","_winlogbeat_collector_node_id":"JUMPBOX","_winlogbeat_winlog_event_data_FWLink":"https://go.microsoft.com/fwlink/?linkid=37020&name=TrojanDownloader:O97M/Donoff!rfn&threatid=2147709062&enterprise=0","_winlogbeat_winlog_process_thread_id":4108,"_winlogbeat_winlog_api":"wineventlog","message":"Windows Defender has detected malware or other potentially unwanted software.\n For more information please see the following:\nhttps://go.microsoft.com/fwlink/?linkid=37020&name=TrojanDownloader:O97M/Donoff!rfn&threatid=2147709062&enterprise=0\n \tName: TrojanDownloader:O97M/Donoff!rfn\n \tID: 2147709062\n \tSeverity: Severe\n \tCategory: Trojan Downloader\n \tPath: file:_C:\\Users\\Administrator\\Downloads\\26de80e3bbbe1f053da4131ca7a405644b7443356ec97d48517f1ab86d5f1ca5\n \tDetection Origin: Local machine\n \tDetection Type: Concrete\n \tDetection Source: User\n \tUser: JUMPBOX\\Klondike57Capsule\n \tProcess Name: Unknown\n \tSecurity intelligence Version: AV: 1.349.510.0, AS: 1.349.510.0, NIS: 0.0.0.0\n \tEngine Version: AM: 1.1.18500.10, NIS: 0.0.0.0","_winlogbeat_winlog_provider_guid":"{11CD958A-C507-4EF3-B3F2-5FD9DFBD2C78}","_winlogbeat_agent_type":"winlogbeat","_winlogbeat_winlog_provider_name":"Microsoft-Windows-Windows Defender","_winlogbeat_winlog_process_pid":1776,"host":"ip-172-31-26-190","level":6,"version":"1.1","_replayed_log":"true"}

Agent Status (Event 1150)

{"_winlogbeat_log_level":"information","_winlogbeat_@metadata_type":"_doc","_winlogbeat_event_created":"2021-09-11T14:25:27.313Z","_winlogbeat_agent_id":"56231ac0-2bd0-40e3-860f-04595b12f20e","_winlogbeat_winlog_opcode":"Info","_winlogbeat_@metadata_beat":"winlogbeat","_winlogbeat_ecs_version":"1.5.0","_winlogbeat_event_code":1150,"_winlogbeat_tags":["windows"],"_winlogbeat_event_provider":"Microsoft-Windows-Windows Defender","_beats_type":"winlogbeat","_winlogbeat_winlog_user_domain":"NT AUTHORITY","_winlogbeat_winlog_user_identifier":"S-1-5-18","_winlogbeat_agent_name":"GRAYLOGMEMBER1","_winlogbeat_winlog_event_id":1150,"_winlogbeat_winlog_user_type":"User","_winlogbeat_host_name":"GRAYLOGMEMBER1.grayloglab.local","_winlogbeat_winlog_user_name":"SYSTEM","_winlogbeat_winlog_channel":"Microsoft-Windows-Windows Defender/Operational","_winlogbeat_winlog_computer_name":"GRAYLOGMEMBER1.grayloglab.local","_winlogbeat_event_kind":"event","_winlogbeat_collector_node_id":"GRAYLOGMEMBER1","_winlogbeat_winlog_process_thread_id":1500,"_winlogbeat_winlog_api":"wineventlog","message":"Endpoint Protection client is up and running in a healthy state.\n \tPlatform version: 4.18.2108.7\n \tEngine version: 1.1.18500.10\n \tSecurity intelligence version: 1.349.518.0","_winlogbeat_@timestamp":"2021-09-11T14:25:25.906Z","_winlogbeat_agent_version":"7.9.0","_winlogbeat_winlog_provider_guid":"{11CD958A-C507-4EF3-B3F2-5FD9DFBD2C78}","_winlogbeat_agent_type":"winlogbeat","_winlogbeat_winlog_provider_name":"Microsoft-Windows-Windows Defender","_winlogbeat_agent_ephemeral_id":"471edb61-c9f5-4710-8af1-db6f63b0a47d","_winlogbeat_@metadata_version":"7.9.0","_winlogbeat_winlog_record_id":17349,"_winlogbeat_agent_hostname":"GRAYLOGMEMBER1","_winlogbeat_winlog_process_pid":2212,"host":"ip-172-31-26-190","level":6,"version":"1.1","_replayed_log":"true"}

What is Provided

  • Parsing, normalization, and enrichment of Defender Antivirus events.

  • Severity and file path normalization.

  • GIM categorization and enforcement fields.

  • A Spotlight dashboard.

Events Processed by This Technology Pack

The pack processes the following Microsoft Defender Antivirus event groups. Events outside these groups receive generic processing.

  • Malware Detection and Response (1006-1008, 1015, 1116-1119)

  • Scan and Quarantine Activity (1000-1014)

  • Engine, Signature, and Platform Updates (2000-2014)

  • Agent Status and Configuration (1150, 5000-5012)

GIM Categorization

GIM categorization is provided for the following Microsoft Defender Antivirus events.

Parsed Fields

The following fields are parsed and normalized from Microsoft Defender Antivirus events.

Microsoft Defender Antivirus Spotlight

This spotlight offers a dashboard with 2 tabs:

Overview

Agent Activity