Skip to content

N-Able AV Defender

Event Logs

Unknown

Application specific files

\Program Files (x86)\N-able Technologies\Windows Agent\log\AVDefenderSecurityEvents.log

Example
[GeneralEventsDataCollector] 2021-10-28 04:36:24,762 WARN  com.nable.agent.AVDefenderMaintenance.GeneralEventsDataSubmit Event message: <JSON DATA>

<unknown start>\N-Able Technologies\AVDefender\Logs

\Program Files (x86)\N-able Technologies\Tools\log\EndPointSDK.log

Registry

Quarantine

  • \Program Files\N-able Technologies\AVDefender\Quarantine\cache.db\
    • table: entries
    • fields: Quarid, path, threat, status, size, quartime, acctime, modtime, scanflags, usersid
    • notes: timestamps are unix timestamps

References