MZ@ !L!This program cannot be run in DOS mode. $;=߉ZSZSZSӬZSQZSRichZSPEd.}" ,L` %8.rdata@@.rsrc @@.} lPP.}$8.rdata8.rdata$voltmdP.rdata$zzzdbg .rsrc$01(.rsrc$02 ՠ(ȇx'/uHkP^.}0H %(?@EXFpGHLRS~0H`x9x 8Ph34r(@X p             0 @ P ` p             0 @ P ` p       '( )H+,>(./P0`02|5x69@; =L* Yjh^xb\g0l mprTud}H| ď T  p< P^<@h\lMUI}J`_Neֶn MUI he-IL  .   . :         Defender      UpToDate     CFA ASRN/A   %1                  MDE  MDE   MDE   MDE     CFA (  )PA ASR (  )   %1         [Running] [Stopped][Paused][Start Pending]PA[Stop Pending][Continue Pending][Pause Pending] [Unknown][Boot][System][Auto][Manual] [Disabled][Normal][Passive Mode][SxS Passive Mode][EDR Block Mode][Passive Audit Mode] [Not running]PA0   ''     .      VMNameVMSize  VMLocationSubscriptionId ResourceGroupVmId OSVersion         PageFile  -PageFile    PageFile  - PageFile   - Azure AD     Azure AD    OS   Proxy  WinHTTP    - AAD - MEM       -  MDM  -  SCCM&  Microsoft Endpoint Manager                    - "  -        AAD Connect  DNS  MDE - ConfigMgr EDR   Sense  Sense  Sense     GUID       DiagTrack (UTC)      Sense MachineAuth    Sense    (     *      MicrosoftPA Defender AV  Defender AV  Defender AV  Defender AV    Defender AV   Defender AV Defender AV!  SSL  Defender AV Proxy  Defender AV      Windows"     Windows      Defender    Defender" Defender     )       Defender+       Defender SmartLockerDefender       DefenderPA\       - URL   .   ,  : %1 ServiceURLss   - URL     Microsoft Defender    (CnC)  . %1   %2   - URL     Microsoft Defender    (CnC) .     - URL : %1   %2    - URL     Microsoft Defender    (CnC) .     - URL : %1   %2u   - URL     Microsoft Defender    ()  . %1   %2   - URL     Microsoft Defender    () .     - URL : %1   %2    - URL     Microsoft Defender    () .     - URL : %1   %2v   - URL     Microsoft Defender    (AutoIR)  . %1  %2    - URL     Microsoft Defender    (AutoIR) .     - URL : %1   %2    - URL     Microsoft Defender    (AutoIR) .     - URL : %1   %2|   - URL     Microsoft Defender    (SampleUpload)  . %1   %2   - URL     Microsoft Defender    (SampleUpload) .     - URL : %1   %2    - URL     Microsoft Defender    (SampleUpload) .     - URL : %1   %2|   - URL     Microsoft Defender    (MdeConfigMgr)  . %1  %2 PA   - URL     Microsoft Defender    (MdeConfigMgr) .     - URL : %1   %2    - URL     Microsoft Defender    (MdeConfigMgr) .     - URL : %1   %2u   - URL     Microsoft Defender    (OneDs)  . %1   %2   - URL     Microsoft Defender    (OneDs) .     - URL : %1   %2    - URL     Microsoft Defender    (OneDs) .     - URL : %1   %2E      Defender     .   .;         .z  - URL   : %1 - %2.   ,   %3.     ,   %4.L     -  Microsoft Defender  .D     -  Microsoft Defender . -  Microsoft Defender   -         EDR,    - URL   - AV  .    : https://learn.microsoft.com/defender-endpoint/configure-network-connections-microsoft-defender-antivirus!     .   . %1       Defender MAPS, ,      (       ).ApproachingDataLimit: %1PAOverDataLimit: %1 : %1NetworkCostType: %1y   - URL     Microsoft Defender    ( ECS)  . %1   %2     Microsoft Defender    ( ECS)  HTTP 502  .         Azure    .      . %1   %2    - URL     Microsoft Defender    ( ECS) .     - URL : %1   %2PAT        MDE,      . P             MDE: %1}   '   Active Directory'.        Preview    .O        MDE   ,   .    X     32 ,         MDE.PAP         - MDE    : %14       Windows .)%1       .`    PPL   ,   .    Microsoft   . PPLa    Hyper-V       - MDE    : %1?   - MDE      . Windows    MDE MDE AV Windefend WscSvc  Windows SecurityHealth  Windows    MDE WdnisSvc   MDE Defender  ,  .j          Defender.     - N-2   .1     Microsoft Defender          -  Defender.     ,        .           .' -  Microsoft Defenderz        .            .' -  Microsoft Defender0    (CPU)   Sense NDR7     Sense EDR   : %1PA CPU < MDE       MDE      MDE   MDE    MDE+  MDE      K      MpSigStub.exe      .4 MDE Windefend      %1]      Defender  ,     - Microsoft.4 MDE Windefend      %1I  Defender     ,  - Microsoft.9-  MDE    (%1)   .F  - :  '%1'       .)     Windows Defender.P        MDE,      .'  Windows Defender  .I    -  Microsoft Defender    E    Azure Active Directory       M365PAM       Microsoft Defender   )   MDE   '   MDE   )    MDE   .       MDE Cyber     MDE/   MDE ProgramData   (    MDE   )    MDE   z                  .    %1`  .      Cyberthrottling,      MDATP.{       Microsoft Monitoring Agent (MMA),          .U              .   MDE$    AAD .   AAD   - MDE    SCP  .      MDE ,     M365(      .1 SharedSignatureRoot    SYSTEM.& SharedSignatureRoot  .7  SharedSignatureRoot     .I   -    SharedSignatureRoot    .     : %16SignatureScheduleDay: %1, SignatureUpdateInterval: %2B           .D      -  Microsoft Defender/SignatureDefinitionUpdateFileSharesSources: %1C           .SignatureFallbackOrder: %1=           .             .     MDE      . ,  .     ,      :    = %1,    GP = %2.TrustedPublishersO       (SCP)    Active Directory.3   (SCP)    : %10   (SCP)    .d     - Azure AD    - SCP    - Enterprise DRS.N       (SCP)    Active Directory.I            (SCP).U      AAD  - MDE     SCP   .t   AAD   - MDE    SCP  .      MDE ,  .I  -  SCCM   -     MDE.Configuration Manager     . Defender           - Configuration Manager.     ,     '    Configuration Manager'.     .*       .F    .    Microsoft   .3 Microsoft Defender    - CVE-2022-232781 Microsoft Defender    -     : %1.m        .         .E    Microsoft Endpoint Configuration Manager .g       %1  : %2.      ,   : %3'     : %1.            .    Microsoft        - OrgID . :    - OrgID ,   MDE       .  Z     '      '    OpsMgr.]   MMA (Microsoft Monitoring Agent)         .-      - Azure.        .     ,   'Windows Time'       .          ,       - BIOS . WindowsTimeF      System Center Endpoint Protection: %1.                 Defender   .&     .   - Microsoft Defender   .  ,      .            Microsoft Defender   .5   Microsoft Defender   &     .   - Microsoft Defender   .  , Microsoft Endpoint Manager             Microsoft Defender   .'      Microsoft  .   - Microsoft Defender   .  ,          .         MDE.B   Azure Active Directory     Microsoft   .   - Microsoft Defender   .  ,             .          .A     - Azure Active Directory-  .E   - Microsoft Defender   .  ,           Microsoft Defender         Azure Active Directory .     Azure Active Directory   Defender        - SCP  .&  -    .C   - Microsoft Defender   .  ,      (SCP)         - Azure AD.    - SCP   - Enterprise DRS.   - SCP   AAD - SCP  -   .   ,  .#        .   - Microsoft Defender   .  ,          .     .        .     AAD Connect.   - Microsoft Defender   .  ,          - AAD Connect.       - AAD,      .      ;     - Windows Server 2012 R2  DNS.O   - Microsoft Defender   .  ,         DNS.     /   - DNS .   - DNS     . Active Directory   - DNS      (  ).   ,  .  .   - Microsoft Defender   .  ,      .         .   .   - Microsoft Defender   .  ,           - MEM.         MDE.  .        .  ,        .          MDE.   .   - Microsoft Defender            - MEM.  ,     .  .   - Microsoft Defender            - MEM.  ,       - MEM.N        - ImageState   '%1'  .             Sysprep   - '%1'.    Microsoft   .    Windows6  ImagePath      .Q     - ImagePath ( %1)      %2 .,       SenseMDE - ConfigMgr   Configuration Manager - Microsoft Defender   .           .   ,           .6   Microsoft Endpoint Configuration Manager     Configuration Manager - Microsoft Defender   .       ,       MDE-Management  .    %%TEMP%% - %%TMP%%  .     - Windows Defender      .      TEMP - TMP.     %%SystemRoot%%\TEMP   .       .f %%TEMP%%  .      Windows Defender    .A  %%TEMP%%      /. %%TEMP%%      .  TEMP            .   %%TEMP%%    .  ,       TEMP - TMP    (%%SystemRoot%%\TEMP   ).R[Please note the device has multiple MMA (Microsoft Monitoring Agent) workspaces.][If the device is onboarded to Defender for Endpoint via ASC (aka Azure Defender for servers) integration, then it is recommended to remove the MDE workspace to avoid cyber upload issues. ] [For more information on ASC integration with Defender for Endpoint please refer to the article.][MDE in Azure]~[This machine has failed to onboard due to missing permissions for registry key HKLM_System_CurrentControlSet_Services_Sense.][This can happen due to interference from 3rd party security products or if SYSTEM account full control permissions are missing for HKLM_System_CurrentControlSet_Services_Sense. The permissions found for SYSTEM account are: %1]P[Please note that this server does not have the modern unified agent installed.][Unified agent for downlevel servers is not installed on this device. It is recommended to install the new agent for optimal performance and protection capabilities. For more information refer to the documentation]H[Onboard Windows servers to the Microsoft Defender for Endpoint service][[Policies assignment failure occurred because of the following environment variable(s): %1]*[The device was successfully onboarded to Microsoft Defender for Endpoint and was able to download the endpoint security policies from MEM. However, there was a failure during the assignment of the policies. ] [ Please remove any non-existing path(s) from the above system environment variable(s).]7[Set environment variables in the System Control Panel]k[Policies assignment failure occurred since Dynamic Fair Share Scheduling (DFSS) is enabled on the device.]C[The device was successfully onboarded to Microsoft Defender for Endpoint and was able to download the endpoint security policies from MEM. ] [ However, there was a failure during the assignment of the policies due to API limitation that can occur when DFSS is enabled. ] [ Please contact Microsoft support for assistance.]O[Device is not up-to-date and does not have anti-spoofing capability deployed.][Please ensure you deploy the recommended security patch to protect the device from spoofing, for more information refer to the links.]2[Microsoft Defender for Endpoint - CVE-2022-23278]4[Microsoft Defender for Endpoint - Threat Analytics]Y[Device is running with an old version of the Microsoft Defender for Endpoint EDR sensor]O[Please update the sensor to ensure you have optimal protection and stability.]7[Microsoft Defender for Endpoint update for EDR Sensor][This machine has failed to onboard as MsSense.exe crashed during initialization phase for TelLib.dll.] [ The error from the crash was: %1] [This can happen if the SYSTEM account does not have permissions to write to the expected path (ProgramData\Microsoft\Windows Defender Advanced Threat Protection\Cyber).] [ Please validate the ACLs in the path and reset the permissions from parent folder if needed.]G[Device is anti-spoofing capable but is not yet registered with cloud.]n[Please ensure connectivity to EDRCloud CnC URLs is not blocked. Contact Microsoft support if issue persists.]O[A configuration or dependency is preventing Network Protection from starting.]V[Please review this error message to understand the blocking issue and resolve it: %1]c[Supported TLS ciphers are not enabled on this machine. This can affect connectivity to MDE cloud.][Please inspect the configured ciphers (within HKLM\SOFTWARE\Policies\Microsoft\Cryptography\Configuration\SSL\00010002) to ensure it contains minimum required ciphers for connectivity to MDE cloud.]$[Cipher suites and TLS requirements]d[TLS 1.2 client protocol is not enabled on this machine. This can affect connectivity to MDE cloud.][Please confirm that TLS 1.2 client is enabled (within HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Client).]PAZ[ECDH ciphers are not enabled on this machine. This can affect connectivity to MDE cloud.][Please confirm that ECDH KeyExchangeAlgorithm is enabled (within HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\KeyExchangeAlgorithms\ECDH).][Basic URL test failed][NetworkProtection component is disabled or failed URL check test. This may indicate a presence of a network redirector (Ex: Cisco Umbrella).]PA  :  mde_cfa_evaluation    CFA      MdeDiag6   CFA (  )     - CFA  $ %1      I  CfaTrustChecks.txt        > %1   - CFA      .b       -  AV         .7 %1   - CFA      .5 %1   - CFA     .9%1   - CFA      : %2.E%1   - CFA    -   : %2.; -  AV         .G -  AV         (  ). : %1  CFA: - : %1, : %2  :% - TaintType: %1, TaintReason:  %2 : %1 (%1 )PA[ASR %1 GUID '%2' (: %3)  /        .Q     - GUID   ASR      .ASR %1 GUID '%2' (: %3)   .    GUID    (, 56a863a9-875e-4185-98a7-b882c64b5ce5).M    - GUID   ASR     .e-  ASR '%1' (: %2)  /        -.Q      -  ASR     .ASR %1 GUID '%2' (: %3)  GUID .  : xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx (, 56a863a9-875e-4185-98a7-b882c64b5ce5).PAi  - GUID   ASR         GUID    .[ASR Exclusion '%1' (source: %2) contains a parent-directory ('..') segment. After resolving '..' the effective excluded path may be much broader than the literal entry suggests, silently expanding the exclusion beyond its intended scope.][Replace the ASR exclusion entry with a fully-resolved absolute path that does not contain '..' segments. Recent versions of Microsoft Defender reject non-canonical exclusion entries at config load time.]    Defender?'   Defender'          ,           Windows - Azure.   Defender Diagnostic Insights  Windows %1.     ?  ' '.     .          ,         .      %1 .6    -    Defender?   Defender       Windows,     ,  ,   ,    .      -    Defender  %1.PAPPPPL     LUA. `       LUA. D    LUA. @   - LUA. <    LUA . <   - LUA. T  LUA  -  . x        . 4VS_VERSION_INFO e e?xStringFileInfoT040D04B0LCompanyNameMicrosoft Corporation3FileDescription   Microsoft Defender   BInternalNamedefenderdiag.dll.LegalCopyright Microsoft Corporation. All rights reserved.ROriginalFilenamedefenderdiag.dll.muij%ProductNameMicrosoft Windows Operating System;FileVersion4.18.26060.3008 (df1b0eba8e0e68e7272235d6dea4de3285c715b9)DProductVersion4.18.26060.3008DVarFileInfo$Translation PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD%0%w *H %h0%d10  `He0\ +7N0L0 +70 010  `He |d% [T' /+㑐Δ֠ 003zkճz0  *H  01 0 UUS10U Washington10URedmond10U Microsoft Corporation1.0,U%Microsoft Windows Production PCA 20110 260219193722Z 261017193722Z0p1 0 UUS10U Washington10URedmond10U Microsoft Corporation10UMicrosoft Windows0"0  *H 0  xT 8+;H'h<&s7\A};_=)ؔ6- 9 5p^WO$:dBAFO 5frvYRU_t% 0b4 ^=݌vOr5HT d)#r'ҳ'ϙ;V%=(R64.ou+j A`p5]N0>ivWo[3Tz+:4aCCl@U>r#uN^7v0r0U%0 +7 +0U:a8B~J$(0EU>0<:0810U Microsoft Corporation10U 501107+5068660U#0)9ėx͐O|US0WUP0N0LJHFhttp://www.microsoft.com/pkiops/crl/MicWinProPCA2011_2011-10-19.crl%200a+U0S0Q+0Ehttp://www.microsoft.com/pkiops/certs/MicWinProPCA2011_2011-10-19.crt0 U00  *H  T?it:]?T]h dzBs=oY^Sxg +OUJ%⩺v/VA'aQ=5\[ݻF,` 4r̅/Ag?oԗEHBNN,g? QDpt uWtu gM.uV& h{Mp9jÂ,N&&-ƶ: FF2󨺇0P0t\&؞p >ys00 avV0  *H  01 0 UUS10U Washington10URedmond10U Microsoft Corporation1200U)Microsoft Root Certificate Authority 20100 111019184142Z 261019185142Z01 0 UUS10U Washington10URedmond10U Microsoft Corporation1.0,U%Microsoft Windows Production PCA 20110"0  *H 0  . i!i33T ҋ8-|byJ?5 pk6u1ݍp7tF([`#,GgQ'rɹ;S5|'# oFnhttp://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0  *H  |qQyn9>\` QfG=*hwLb{Ǻz4KbzJ7-W|=ܸZij:ni!7ށugӓW^)9-Es[zFX^gl5?$5 uVx,Јߺ~,c#!xlX6+̤-@EΊ\k>p* j_Gc 26*pZBYqKW~!<ŹE ŕ]b֠c uw}=EWo3wbY~10 001 0 UUS10U Washington10URedmond10U Microsoft Corporation1.0,U%Microsoft Windows Production PCA 20113zkճz0  `He0 *H  1  +70 +7 10  +70/ *H  1" g=hfh{D}qV@_0˱+~[0B +7 1402Microsofthttp://www.microsoft.com0  *H L+Oe=q Z%e|zsP9v+ȟμ1/y;%_֖bݫkgR;k۵~Sʢ,mt"ef(TW _wpMZp+K&%$jlOpt*hk*Gv o9K -Eaa^mXʢ:jr ,Æ->ܹ dǢ}atRqT)A{Fn$R0 +710| *H m0i10  `He0R *H  A=09 +Y 010  `He 95\ 5ڋck4ooϒ]j1vl20260622202611.533Z0Ѥ01 0 UUS10U Washington10URedmond10U Microsoft Corporation1%0#U Microsoft America Operations1'0%U nShield TSS ESN:7F00-05E0-D9471%0#UMicrosoft Time-Stamp Service0 03n9o|I0  *H  0|1 0 UUS10U Washington10URedmond10U Microsoft Corporation1&0$UMicrosoft Time-Stamp PCA 20100 260219193949Z 270517193949Z01 0 UUS10U Washington10URedmond10U Microsoft Corporation1%0#U Microsoft America Operations1'0%U nShield TSS ESN:7F00-05E0-D9471%0#UMicrosoft Time-Stamp Service0"0  *H 0 8l<,G^:^l8mNvj\Kѹdsy$ CӪs\~׼[ Z0!*' aY<0//LzX(,X-tW=$߯HN]XHuRne{kbEE]jᐗoAMei.YF<[\Z܋0I99S>t  aċl3IԪ+&U4o.5_oW&?4:kOf+|!Y*OBN5ƹ;xLb=(]b6-%ԑJn4S2y ;LY1RA=.]fVT]o]vm]O(%5uJ*+PGD35^RN8hZj<9՝Nv&sE_Utd1b(]sFՉS*Kw,+3{+V'[>-I0E0U  fb\.<d0U#0]^b]eS5r0_UX0V0TRPNhttp://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl0l+`0^0\+0Phttp://www.microsoft.com/pkiops/certs/Microsoft%20Time-Stamp%20PCA%202010(1).crt0 U00U% 0 +0U0  *H  y6rUp)Ѣy9ƶLX2`O6H|&zS}toI353 OH Ik\@,&Noq쪥CY3ױv5ٕ8 4k2j$.6)1fXb}+<([4}0?L'-G(jTՔK}n_G$5SdwS8n:-txXZ4@Bu8ۧw߄Tpu~jC 7(}\w<B`PĴ- _y>E-I|(-}x$`Bѣqqx+*:pmG,(:WFDO0} Y$^Ԋ>I5u1Zy)nw d':27|(|B>%N#Yơ\_͑8ߘvw/}E*^@ʋj%!fqjWUvb[4,Ci\kMZ0!60q0Y3kI0  *H  01 0 UUS10U Washington10URedmond10U Microsoft Corporation1200U)Microsoft Root Certificate Authority 20100 210930182225Z 300930183225Z0|1 0 UUS10U Washington10URedmond10U Microsoft Corporation1&0$UMicrosoft Time-Stamp PCA 20100"0  *H 0 Lr! y$yՂҩlNu5WlJ⽹>`3\OfSqZ~JZ6gF# w2`}jRDFkvPDq\Q17 8n&S|9azĪri65&dژ;{3[~Rb%j]SVMݼ㑏9,Qpi 6-p15(㴇$ɏ~TUmh;Fz)7EFn20\O,b͹⍈䖬Jq[g`= s}AFu_4 }~ٞE߶r/}_۪~66L+nQsM7t4G|?Lۯ^s=CN39LBh.QFѽjZasg^(v3rק  co 6d[!]_0tعP a65Gk\RQ]%PzlrRą<7?xE^ڏriƮ{>j.00 +70# +7*RdĚhttp://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0  *H  U}*,g1$[rKo\>NGdx=139q6?dl|u9m1lѡ"fg:SMݘx6.Vi {jo)n?Hum m#TxSu$Wݟ=heV(U'$@]='@8)üTB  jBRu6as.,k{n?, x鑲[It 쑀=J>f;O2ٖtLrou04zP X@1Q{p( 6ںL 4$5g+ 挙"'B=%tt[jў>~13}{8pDѐȫ::bpcSMmqjU3XpfM050Ѥ01 0 UUS10U Washington10URedmond10U Microsoft Corporation1%0#U Microsoft America Operations1'0%U nShield TSS ESN:7F00-05E0-D9471%0#UMicrosoft Time-Stamp Service# 0+d(2R=j0~0|1 0 UUS10U Washington10URedmond10U Microsoft Corporation1&0$UMicrosoft Time-Stamp PCA 20100  *H  W0"20260622161207Z20260623161207Z0t0: +Y 1,0*0 W0)0L0 .06 +Y 1(0&0  +Y  0 00  *H  29GK1:h*$׮f")i8sԉhbEwV!Ʉ{}2By&Dwb!+H}TiTmʕY].ꊂbW1f )YyhVa+fy*k}=*D8Tv_~iUfJ;##n𛁂;0/V+k}ǜg޽9|#kRPg%ttvlȖTw(DTYxח%??4AADy| hfbK- ;"؁yɕC88NITI¹DlJIWA%|>H