Microsoft Malware 名词解释

1.id

MachineIdentifier

2.电脑杀毒软件

  • ProductName - Defender state information e.g. win8defender

win8defender 8826520

mse 94873

mseprerelease 53

scep 22

windowsintune 8

fep 7

  • EngineVersion - Defender state information e.g. 1.1.12603.0

70 unique

  • AppVersion - Defender state information e.g. 4.9.10586.0

110 unique

  • AvSigVersion - Defender state information e.g. 1.217.1014.0

8,531 unique

  • IsBeta - Defender state information e.g. false

binary全0,基本没用

3.电脑系统配置

  • RtpStateBitfield (Realtime protection state)

7 unique and NaN 32318

  • IsSxsPassiveMode this a active/passive mode of operation for Windows Defender. If another third party primary antivirus exists on the system, the Defender enters Passive mode.

binary

  • DefaultBrowsersIdentifier

2017 unique

  • HasTpm - True if machine has tpm

可信平台模块(Trusted Platform Module) binary

4.自配杀毒软件

  • AVProductStatesIdentifier - ID for the specific configuration of a user's antivirus software

28,970 unique

  • AVProductsInstalled - NA

安装数量

  • AVProductsEnabled - NA

激活数量

  • IsProtected - This is a calculated field derived from the Spynet Report's AV Products field. Returns: a. TRUE if there is at least one active and up-to-date antivirus product running on this machine. b. FALSE if there is no active AV product on this machine, or if the AV is active, but is not receiving the latest updates. c. null if there are no Anti Virus Products in the report. Returns: Whether a machine is protected.

binary $ null

5.电脑位置

  • CountryIdentifier - ID for the country the machine is located in

This has 222 unique int64 IDs. Wikipedia cites 255+ countries and independent territories. If these are exact country codes, then Austria (43) has the highest number of rows in this data set, while USA(001) has just 2 %.

  • CityIdentifier - ID for the city the machine is located in

1,07,366 unique cities and huge number(~5%) of NaNs.

  • OrganizationIdentifier - ID for the organization the machine belongs in, organization ID is mapped to both specific companies and broad industries

There are 49 unique organisations, 50% of the computers being under one org, another 25% not-classified. Here's a breakup of the top 5 values

  • GeoNameIdentifier - ID for the geographic region a machine is located in

292 geographic regions, a machine is located in.

  • LocaleEnglishNameIdentifier - English name of Locale ID of the current user

276 locale int64 IDs. "A locale is neither a language nor a country, the same language may be spoken in multiple countries (often with subtle differences) and a single country may speak multiple languages. A locale is therefore an area where a p

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值