Defender - Computer Status (Sensor)
This page shows how to create the Defender - Computer Status sensor by hand in the Tanium Console.
What it returns: one row per Windows endpoint with Defender's running mode (Normal, Passive, EDR Block Mode), whether the antivirus and real-time protection are on, tamper protection, the platform version, and how old the signatures are.
It is built from Get-MpComputerStatus. Running that cmdlet raw through a sensor returns 40+ properties as separate lines, which can't be sorted or filtered. This sensor picks the useful ones and returns them as columns.
Use it with the built-in sensor
Get-MpComputerStatus only answers when the WinDefend service is running. On machines where Defender is stopped (common when another antivirus is installed), this sensor returns Error: Service not running. For versions on those machines, use the built-in Microsoft Defender AntiMalware Details sensor, which reads them even when the service is stopped. See Defender Vulnerability Remediation for how the two are used together.
Test status
Tested on Windows 11 Pro with Windows PowerShell 5.1, run from a PowerShell prompt as the signed-in user. It has not yet been run through Tanium as SYSTEM.
Before you start
- You need a role that can create sensors in the content set you plan to use.
- If a sensor named Defender - Computer Status already exists, edit it instead of creating a second one. Sensor names must be unique.
- Copy the script with the copy button on its code block so nothing is changed.
Create the sensor
Step 1: Open a new sensor
- Sign in to the Tanium Console.
- Open the main menu, then go to Administration > Content > Sensors.
- Click Create Sensor.
Step 2: Details section
| Field | Value |
|---|---|
| Name | Defender - Computer Status |
| Description | Returns Microsoft Defender running mode, antivirus and real-time protection state, tamper protection, platform version, and signature version and age. Returns Not Applicable when Defender is not installed and Error: Service not running when the WinDefend service is stopped. |
| Content Set | Your own custom content set (for example the one you use for lab or custom sensors) |
Step 3: Settings section
| Field | Value |
|---|---|
| Category | Miscellaneous (or any category you use for custom sensors) |
| Result Type | Text |
| Max Sensor Age | 1 and set the unit dropdown to Hours. Signatures update a few times a day, so an hour is fresh enough |
| Max String Age | Leave Enable unchecked |
| Max Strings | Leave Enable unchecked |
| Ignore case in result values | Checked |
| Hide this sensor from sensor lists and parse results | Unchecked |
| Split into multiple columns | Checked |
Step 4: Column settings
After you check Split into multiple columns:
- Set Delimiter to
|(the pipe character, Shift + Backslash on a US keyboard). - Add these 9 columns in this order. The order must match, because the script returns the values in this order.
| Index | Column Name | Value Type | Ignore case | Hidden |
|---|---|---|---|---|
| 0 | Running Mode | Text | Checked | Unchecked |
| 1 | Service Enabled | Text | Checked | Unchecked |
| 2 | AV Enabled | Text | Checked | Unchecked |
| 3 | Real-Time Protection | Text | Checked | Unchecked |
| 4 | Tamper Protected | Text | Checked | Unchecked |
| 5 | Platform Version | Version | Checked | Unchecked |
| 6 | Signature Version | Version | Checked | Unchecked |
| 7 | Signature Last Updated | Text | Checked | Unchecked |
| 8 | Signature Age (Days) | Integer | Checked | Unchecked |
The console does not have a String type. Use Text.
Step 5: Parameters section
Leave it empty. This sensor has no parameters.
Step 6: Scripts section
For each platform in the table: click the platform tab on the left, check Enable sensor for [platform] platform, set Query Type in the top right, click inside the script editor, press Ctrl + A, press Delete, then paste the script for that platform.
| Platform | Enable | Query Type | Script |
|---|---|---|---|
| Windows | Checked | PowerShell | Windows script below |
| Linux | Checked | UnixShell | Stub below, returns Not Applicable |
| Mac | Checked | UnixShell | Stub below, returns Not Applicable |
# Tanium sensor: Defender - Computer Status (Windows)
#
# Sensor settings
# Script type : PowerShell
# Parameters : none
# Result type : Text, split into columns, delimiter |
# Columns : Running Mode | Service Enabled | AV Enabled | Real-Time Protection |
# Tamper Protected | Platform Version | Signature Version |
# Signature Last Updated | Signature Age (Days)
# (Platform Version and Signature Version = Version,
# Signature Age (Days) = Integer, others = Text)
#
# Status values in the Running Mode column when Defender can't be read:
# Not Applicable The WinDefend service does not exist (Defender removed or never installed)
# Error: Service not running WinDefend exists but is stopped, so Get-MpComputerStatus can't answer
# Error: Status unavailable WinDefend is running but Get-MpComputerStatus failed
# Read-only: nothing on the endpoint is changed.
# Run as 64-bit so the Defender module and WMI provider load from System32.
if ([Environment]::Is64BitOperatingSystem -and -not [Environment]::Is64BitProcess -and $PSCommandPath) {
$ps64 = Join-Path $env:SystemRoot 'Sysnative\WindowsPowerShell\v1.0\powershell.exe'
& $ps64 -NoProfile -NonInteractive -ExecutionPolicy Bypass -File $PSCommandPath
exit $LASTEXITCODE
}
$d = '|'
function Write-StatusRow([string]$status) {
Write-Output ((@($status) + @('N/A') * 8) -join $d)
}
$svc = Get-Service -Name 'WinDefend' -ErrorAction SilentlyContinue
if (-not $svc) {
Write-StatusRow 'Not Applicable'
exit 0
}
if ($svc.Status -ne 'Running') {
Write-StatusRow 'Error: Service not running'
exit 0
}
try {
$s = Get-MpComputerStatus -ErrorAction Stop
}
catch {
Write-StatusRow 'Error: Status unavailable'
exit 0
}
$sigDate = $null
if ($s.AntivirusSignatureLastUpdated) {
$sigDate = $s.AntivirusSignatureLastUpdated.ToString('yyyy-MM-dd HH:mm')
}
$raw = @(
$s.AMRunningMode
$s.AMServiceEnabled
$s.AntivirusEnabled
$s.RealTimeProtectionEnabled
$s.IsTamperProtected
$s.AMProductVersion
$s.AntivirusSignatureVersion
$sigDate
$s.AntivirusSignatureAge
)
# Never return a blank column
$fields = foreach ($v in $raw) {
if ($null -eq $v -or "$v" -eq '') { 'Unknown' } else { ("$v" -replace '[\r\n|]', ' ').Trim() }
}
Write-Output ($fields -join $d)
Step 7: Save
- Scroll to the bottom of the page and click Save.
- If the console reports that the name already exists, cancel and edit the existing sensor.
Step 8: Test on a few machines first
- Go to Interact.
- In the question bar, enter
Get Computer Name and Defender - Computer Status from all machines with Computer Name contains "<hostname>", replacing<hostname>with a Windows machine where Defender is running. - Check the results:
- You see 9 columns. If everything is in one column with
|inside the value, the column split was not saved. Edit the sensor and recheck Step 4. - Running Mode shows
NormalorPassive, and Platform Version shows a value like4.18.26080.4.
- You see 9 columns. If everything is in one column with
Example result (values are illustrative):
Reading the results
| Column | What it tells you |
|---|---|
| Running Mode | Normal (Defender is the active antivirus), Passive (another antivirus is primary, Defender still updates), EDR Block Mode, SxS Passive Mode, or one of the status values below |
| Service Enabled | Whether the Defender antimalware service is enabled |
| AV Enabled | Whether antivirus protection is on |
| Real-Time Protection | Whether real-time scanning is on |
| Tamper Protected | Whether tamper protection is on |
| Platform Version | The Defender antimalware platform version, for example 4.18.26080.4. This is the version most Defender CVEs are fixed in |
| Signature Version | The security intelligence version |
| Signature Last Updated | When signatures last updated, in the endpoint's local time |
| Signature Age (Days) | Days since the last signature update. Above 7 usually means updates are failing |
Status values
When the sensor can't read Defender, the first column holds one of these and the other columns show N/A:
| Running Mode | Meaning |
|---|---|
Not Applicable |
The WinDefend service does not exist. Defender was removed, or the endpoint is not Windows |
Error: Service not running |
WinDefend exists but is stopped, usually because another antivirus is installed. Use Microsoft Defender AntiMalware Details for versions |
Error: Status unavailable |
WinDefend is running but Get-MpComputerStatus failed. Check the Defender WMI provider on that machine |
Limits
- No engine version column. The built-in Microsoft Defender AntiMalware Details sensor already returns Engine Version and Product Version, so this sensor doesn't repeat them.
- Signature Last Updated is returned as Text, so it sorts as text.
yyyy-MM-dd HH:mmsorts correctly as text anyway. - Read-only. The sensor never changes anything on the endpoint.