EPA2
tail -f /var/log/ns.log | GREP_COLOR=’1;31′ grep –color=always ‘CaseID.*’ FIREWALL sys.client_expr(« app_0_FIREWALL_0_0_ENABLED_==_TRUE[COMMENT: Generic Firewall Product Scan] ») bitlocker sys.client_expr(« sys_0_REG_PATH_==_HKEY\\\\_LOCAL\\\\_MACHINE\\\\\\\\SYSTEM\\\\\\\\CurrentControlSet\\\\\\\\Control\\\\\\\\BitlockerStatus\\\\\\\\BootStatus_VALUE_==_1[COMMENT: Registry] ») EDR MDE MsSense.exe (Microsoft Defender for Endpoint Sensor) Rôle : C’est le capteur EDR (Endpoint Detection and Response) https://learn.microsoft.com/fr-fr/defender-endpoint/microsoft-defender-antivirus-windows ANTIVIRUS real time MsMpEng.exe (Microsoft Malware Protection Engine) Rôle : C’est le moteur antivirus…