The VMware Carbon Black Tech Zone is live! Checkout this great resource: Mastering Carbon Black Audit & Remediation.

Status of Windows Defender Firewall

Description: This query looks to see the status of the windows defender firewall status. Windows defender should be enabled in enterprise environments even if there is an enterprise grade firewall to improve defense in depth and make it more difficult for attackers to move laterally.

What The Data Shows: The data shows the status of the windows defender firewall on windows machines.

SQL: 

SELECT display_name,status,start_type from services where lower(name) = "mpssvc";

 

 

2 Comments
jnelson
Carbon Black Employee
Status changed to: Approved
 
mailboxpickup1
New Contributor II

Can you share a method to detect if the running process for Windows defender is running on a host?