.. generated, remove this comment to keep this file ``defender.evtx`` ================= .. code-block:: console $ target-query -f defender.evtx .. list-table:: Details :widths: 20 80 * - Module - ``os.windows.defender.MicrosoftDefenderPlugin`` * - Output - ``records`` **Module documentation** Plugin that parses artifacts created by Microsoft Defender. This includes the EVTX logs, as well as recovery of artefacts from the quarantine folder. **Function documentation** Parse Microsoft Defender evtx log files