ThreatCheck

AV signature detection verification (legacy)

Overview

ThreatCheck is a legacy verifier that scans compiled binaries against Windows Defender.

Note: ThreatCheck provides binary signals. For graduated rewards, use Elastic Security.

Installation

  1. Download from ThreatCheck releases
  2. Place on DEVBOX: C:\tools\ThreatCheck.exe

Configuration

windows:
  threatcheck:
    enabled: true
    path: "C:\\tools\\ThreatCheck.exe"
    timeout: 60

Reward Mapping

OutcomeReward
No detection1.0
Detected0.5
Scan error0.3