Reference tables
The following section contains some useful reference tables for various aspects of MDE.
Processes
Here’s an overview of the MDE processes per operating system.
Windows 11, Windows 10, Windows Server 2022, and Windows Server 2019, (Server 2012 R2 and Server 2016 with the unified agent)
Cold snack
On Windows Server 2012 R2 and 2016, EDR components initially get installed in C:\Program Files
. However, you will find that after monthly updates for the EDR, sensor services will start running from the C:\Programdata\Microsoft\Windows Defender Advanced Threat Protection\Platform\<VERSION>
directory instead.
The following table shows the processes, their location, and their purposes:
Process |
Location |
Purpose |
|
|
Antivirus command... |