Skip to content

Microsoft Defender / Antivirus detections removed in new releases  #168

Open
@AnthoLaMalice

Description

@AnthoLaMalice

Hey guys,

I have observed that the latest version of Chainsaw no longer seems to report Microsoft Defender/AV detection.

I ran both v2.9.0 and v2.8.0 on the same log set, which I know contains Microsoft Defender detection for CVE-2021-31207. The default raw output was redirected to a file for testing.

v2.9.0 vs v2.8.0 :

image

As you can see v2.8.0 indeed showed Microsoft Defender detection which is not the case for v2.9.0.

It also seems that with version 2.8.0, if you output your results to a csv or json file, a specific file has been created for AV detection, which is not the case with version 2.9.0.

Is there an explanation for this?

Thanks for your work!

Metadata

Metadata

Assignees

Labels

bugSomething isn't working

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions