Antivirus / EDR
Enumeration
Get-MpComputerStatusGet-AppLockerPolicy -Effective | select -ExpandProperty RuleCollections$ExecutionContext.SessionState.LanguageModeFind-LAPSDelegatedGroupsFind-AdmPwdExtendedRightsGet-LAPSComputersnetsh advfirewall show allprofileswmic /namespace:\\root\securitycenter2 path antivirusproductGet-CimInstance -Namespace root/SecurityCenter2 -ClassName AntivirusProductFirewall
Set-NetFirewallProfile -Profile Domain, Public, Private -Enabled FalseGet-NetFirewallProfile | Format-Table Name, EnabledGet-MpThreatGet-NetFirewallRule | findstr "Rule-Name"Last updated