Integrating Windows Defender logs
Windows Defender is an antivirus software module of Microsoft Windows. As per the 2023 Antivirus Market Report, Windows Defender is the most common free antivirus product for PC users, with around 40% of the market share of free antivirus software. For more information on this, you can check the following link: https://www.security.org/antivirus/antivirus-consumer-report-annual/. Additionally, Microsoft also offers endpoint security solutions for enterprises called Windows Defender for Endpoint. This makes us put more attention on integrating Windows Defender with Wazuh. By default, Wazuh cannot read the Windows Defender logs. Hence, it is important for us to put extra effort into making it possible.
In this section, we’ll learn to push Windows Defender logs to the Wazuh manager. You will learn about the following:
- How to get started with Windows Defender logs
- Setting up the Wazuh agent to collect Windows Defender logs
- Testing...