{"id":26654127,"url":"https://github.com/malice-plugins/windows-defender","last_synced_at":"2026-03-12T07:34:21.088Z","repository":{"id":21329192,"uuid":"92237462","full_name":"malice-plugins/windows-defender","owner":"malice-plugins","description":"Malice Windows Defender AntiVirus Plugin","archived":false,"fork":false,"pushed_at":"2023-03-07T02:57:25.000Z","size":3668,"stargazers_count":38,"open_issues_count":5,"forks_count":21,"subscribers_count":3,"default_branch":"master","last_synced_at":"2025-04-11T07:51:23.804Z","etag":null,"topics":["antivirus","docker","malice","malware","plugin","windows-defender"],"latest_commit_sha":null,"homepage":null,"language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/malice-plugins.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":".github/FUNDING.yml","license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null},"funding":{"patreon":"blacktop_"}},"created_at":"2017-05-24T01:39:14.000Z","updated_at":"2024-11-19T23:31:34.000Z","dependencies_parsed_at":"2024-06-19T19:07:55.163Z","dependency_job_id":"83b88073-bf57-4409-b923-d2dafbfbbe0d","html_url":"https://github.com/malice-plugins/windows-defender","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/malice-plugins/windows-defender","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/malice-plugins%2Fwindows-defender","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/malice-plugins%2Fwindows-defender/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/malice-plugins%2Fwindows-defender/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/malice-plugins%2Fwindows-defender/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/malice-plugins","download_url":"https://codeload.github.com/malice-plugins/windows-defender/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/malice-plugins%2Fwindows-defender/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":30418143,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-03-12T07:30:13.030Z","status":"ssl_error","status_checked_at":"2026-03-12T07:29:54.885Z","response_time":114,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["antivirus","docker","malice","malware","plugin","windows-defender"],"created_at":"2025-03-25T04:57:23.126Z","updated_at":"2026-03-12T07:34:21.069Z","avatar_url":"https://github.com/malice-plugins.png","language":"Go","funding_links":["https://patreon.com/blacktop_"],"categories":[],"sub_categories":[],"readme":"# windows-defender\n\n[![Publish Docker Image](https://github.com/malice-plugins/windows-defender/actions/workflows/docker-image.yml/badge.svg)](https://github.com/malice-plugins/windows-defender/actions/workflows/docker-image.yml)\n[![License](http://img.shields.io/:license-mit-blue.svg)](http://doge.mit-license.org)\n[![Docker Stars](https://img.shields.io/docker/stars/malice/windows-defender.svg)](https://store.docker.com/community/images/malice/windows-defender)\n[![Docker Pulls](https://img.shields.io/docker/pulls/malice/windows-defender.svg)](https://store.docker.com/community/images/malice/windows-defender)\n[![Docker Image](https://img.shields.io/badge/docker%20image-285MB-blue.svg)](https://store.docker.com/community/images/malice/windows-defender)\n\nMalice Windows Defender AntiVirus Plugin\n\n\u003e This repository contains a **Dockerfile** of [Windows Defender](https://www.microsoft.com/en-us/windows/windows-defender) for the malice plugin **malice/windows-defender**\n\n---\n\n### Dependencies\n\n- [ubuntu:bionic (_84.1 MB_\\)](https://hub.docker.com/_/ubuntu/)\n\n## Installation\n\n1. Install [Docker](https://www.docker.io/).\n2. Download [trusted build](https://store.docker.com/community/images/malice/windows-defender) from public [docker store](https://store.docker.com): `docker pull malice/windows-defender`\n\n## Usage\n\n### NOTICE :warning:\n\nSomething has changed in the latest version of Docker `18.09.0` where we now need to use our own seccomp profile found [here](https://raw.githubusercontent.com/malice-plugins/windows-defender/master/seccomp.json)\n\n```bash\ndocker run --init --rm malice/windows-defender EICAR\n```\n\nWith seccomp profile\n\n```bash\ndocker run --init --rm --security-opt seccomp=seccomp.json malice/windows-defender EICAR\n```\n\n### Or link your own malware folder:\n\n```bash\n$ docker run --init --rm -v /path/to/malware:/malware malice/windows-defender FILE\n\nUsage: windows-defender [OPTIONS] COMMAND [arg...]\n\nMalice Windows Defender AntiVirus Plugin\n\nVersion: v0.1.0, BuildTime: 20180903\n\nAuthor:\n  blacktop - \u003chttps://github.com/blacktop\u003e\n\nOptions:\n  --verbose, -V          verbose output\n  --table, -t            output as Markdown table\n  --callback, -c         POST results to Malice webhook [$MALICE_ENDPOINT]\n  --proxy, -x            proxy settings for Malice webhook endpoint [$MALICE_PROXY]\n  --elasticsearch value  elasticsearch url for Malice to store results [$MALICE_ELASTICSEARCH_URL]\n  --timeout value        malice plugin timeout (in seconds) (default: 60) [$MALICE_TIMEOUT]\n  --help, -h             show help\n  --version, -v          print the version\n\nCommands:\n  update  Update virus definitions\n  web     Create a Windows Defender scan web service\n  help    Shows a list of commands or help for one command\n\nRun 'windows-defender COMMAND --help' for more information on a command.\n```\n\nThis will output to stdout and POST to malice results API webhook endpoint.\n\n## Sample Output\n\n### [JSON](https://github.com/malice-plugins/windows-defender/blob/master/docs/results.json)\n\n```json\n{\n  \"windows-defender\": {\n    \"infected\": true,\n    \"result\": \"Virus:DOS/EICAR_Test_File\",\n    \"engine\": \"0.1.0\",\n    \"updated\": \"20171112\"\n  }\n}\n```\n\n### [Markdown](https://github.com/malice-plugins/windows-defender/blob/master/docs/SAMPLE.md)\n\n---\n\n#### Windows Defender\n\n| Infected | Result                    | Engine | Updated  |\n| :------- | :------------------------ | :----- | :------- |\n| true     | Virus:DOS/EICAR_Test_File | 0.1.0  | 20171112 |\n\n---\n\n## Documentation\n\n- [To write results to ElasticSearch](https://github.com/malice-plugins/windows-defender/blob/master/docs/elasticsearch.md)\n- [To create a Windows Defender scan micro-service](https://github.com/malice-plugins/windows-defender/blob/master/docs/web.md)\n- [To post results to a webhook](https://github.com/malice-plugins/windows-defender/blob/master/docs/callback.md)\n- [To update the AV definitions](https://github.com/malice-plugins/windows-defender/blob/master/docs/update.md)\n\n## Issues\n\nFind a bug? Want more features? Find something missing in the documentation? Let me know! Please don't hesitate to [file an issue](https://github.com/malice-plugins/windows-defender/issues/new).\n\n## CHANGELOG\n\nSee [`CHANGELOG.md`](https://github.com/malice-plugins/windows-defender/blob/master/CHANGELOG.md)\n\n## Contributing\n\n[See all contributors on GitHub](https://github.com/malice-plugins/windows-defender/graphs/contributors).\n\nPlease update the [CHANGELOG.md](https://github.com/malice-plugins/windows-defender/blob/master/CHANGELOG.md) and submit a [Pull Request on GitHub](https://help.github.com/articles/using-pull-requests/).\n\n## Credit\n\nMade possible by the awesome work by [@taviso](https://github.com/taviso/loadlibrary)\n\n## License\n\nMIT Copyright (c) 2022 **blacktop**\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmalice-plugins%2Fwindows-defender","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fmalice-plugins%2Fwindows-defender","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmalice-plugins%2Fwindows-defender/lists"}