Skip to content

malice-plugins/windows-defender

Folders and files

NameName
Last commit message
Last commit date

Latest commit

b3fbcf9 · Mar 7, 2023

History

92 Commits
Mar 28, 2022
Mar 23, 2022
Dec 3, 2018
Jul 29, 2018
Jul 29, 2018
Mar 23, 2022
Jun 10, 2017
May 25, 2017
Mar 23, 2022
Mar 28, 2022
May 24, 2017
Nov 12, 2017
Sep 3, 2018
Mar 7, 2023
Mar 7, 2023
Mar 21, 2020
Mar 21, 2020
Dec 3, 2018
Jul 3, 2017
Mar 21, 2020

Repository files navigation

windows-defender

Publish Docker Image License Docker Stars Docker Pulls Docker Image

Malice Windows Defender AntiVirus Plugin

This repository contains a Dockerfile of Windows Defender for the malice plugin malice/windows-defender


Dependencies

Installation

  1. Install Docker.
  2. Download trusted build from public docker store: docker pull malice/windows-defender

Usage

NOTICE ⚠️

Something has changed in the latest version of Docker 18.09.0 where we now need to use our own seccomp profile found here

docker run --init --rm malice/windows-defender EICAR

With seccomp profile

docker run --init --rm --security-opt seccomp=seccomp.json malice/windows-defender EICAR

Or link your own malware folder:

$ docker run --init --rm -v /path/to/malware:/malware malice/windows-defender FILE

Usage: windows-defender [OPTIONS] COMMAND [arg...]

Malice Windows Defender AntiVirus Plugin

Version: v0.1.0, BuildTime: 20180903

Author:
  blacktop - <https://github.com/blacktop>

Options:
  --verbose, -V          verbose output
  --table, -t            output as Markdown table
  --callback, -c         POST results to Malice webhook [$MALICE_ENDPOINT]
  --proxy, -x            proxy settings for Malice webhook endpoint [$MALICE_PROXY]
  --elasticsearch value  elasticsearch url for Malice to store results [$MALICE_ELASTICSEARCH_URL]
  --timeout value        malice plugin timeout (in seconds) (default: 60) [$MALICE_TIMEOUT]
  --help, -h             show help
  --version, -v          print the version

Commands:
  update  Update virus definitions
  web     Create a Windows Defender scan web service
  help    Shows a list of commands or help for one command

Run 'windows-defender COMMAND --help' for more information on a command.

This will output to stdout and POST to malice results API webhook endpoint.

Sample Output

{
  "windows-defender": {
    "infected": true,
    "result": "Virus:DOS/EICAR_Test_File",
    "engine": "0.1.0",
    "updated": "20171112"
  }
}

Windows Defender

Infected Result Engine Updated
true Virus:DOS/EICAR_Test_File 0.1.0 20171112

Documentation

Issues

Find a bug? Want more features? Find something missing in the documentation? Let me know! Please don't hesitate to file an issue.

CHANGELOG

See CHANGELOG.md

Contributing

See all contributors on GitHub.

Please update the CHANGELOG.md and submit a Pull Request on GitHub.

Credit

Made possible by the awesome work by @taviso

License

MIT Copyright (c) 2022 blacktop