Open
Description
Hey guys,
I have observed that the latest version of Chainsaw no longer seems to report Microsoft Defender/AV detection.
I ran both v2.9.0 and v2.8.0 on the same log set, which I know contains Microsoft Defender detection for CVE-2021-31207. The default raw output was redirected to a file for testing.
v2.9.0 vs v2.8.0 :
As you can see v2.8.0 indeed showed Microsoft Defender detection which is not the case for v2.9.0.
It also seems that with version 2.8.0, if you output your results to a csv or json file, a specific file has been created for AV detection, which is not the case with version 2.9.0.
Is there an explanation for this?
Thanks for your work!