Using Defender Status
A read-only dashboard for Microsoft Defender. This page covers installation, the panels, elevation, reports and updates.
Installation
- Download
DefenderStatus.exefrom the latest release. - Optionally verify it against the published
DefenderStatus.exe.sha256:
Get-FileHash .\DefenderStatus.exe -Algorithm SHA256
Compare the output with the contents of the .sha256 file. If the two match, the download is intact.
- Run the executable. There is no installer and nothing to uninstall.
Reading the dashboard
Overview
The overview page is the whole product in one screen:
- Current posture โ a single verdict of Protection active, Needs attention or Protection reduced, with the reason underneath.
- Protection components โ a tile per component. Green means on, amber means worth a look, red means off.
- Signatures and engine โ version and age of the virus definitions, plus engine and product versions.
- Scans โ the last and next quick and full scans.
- Firewall profiles โ domain, private and public.
Detection history
Everything Defender has recorded on the device: the threat name, severity, what action was taken, the affected file and when. Unresolved detections are why the overview can read Needs attention.
Exclusions
Folders, processes and file types Defender is told to skip. This list is worth reading periodically: every entry is a place malware can hide. Reading it requires administrator rights.
Updates
Shows the installed build and the state of the release check. See Updates below.
Settings
Preferences for this app only โ update checks, automatic downloads and pre-release builds. Nothing here changes Defender.
Elevation
Most panels work without administrator rights. The exclusions list is the exception: Windows only exposes configured exclusions to elevated processes. When the app is not elevated it marks the exclusions as unavailable rather than showing an empty list, so you always know the difference between "none" and "cannot read".
Reports
Save report writes a Markdown summary to your Documents folder, named after the device and timestamp. Copy to clipboard puts the same content on the clipboard for pasting into a ticket or chat. Reports describe state only and never change anything.
Updates
On launch, and whenever you press Check now, the app asks the public GitHub Releases API for the newest release of this repository. If a newer version exists it downloads the attached executable, verifies its SHA-256 against the published checksum, and waits. Only when you press Install and restart does it replace the binary: it writes a short helper that waits for the current process to exit, moves the new file into place, and relaunches. If the checksum does not match, the download is deleted and nothing is installed. You can disable the automatic check in Settings.
Building from source
You need the .NET 10 SDK on Windows.
cd app
dotnet publish -c Release -r win-x64 --self-contained true -p:PublishSingleFile=true -o ..\dist
The result is a single dist\DefenderStatus.exe.
Troubleshooting
- Some values show as unknown. Not every Defender build exposes every field. The app reports unknown rather than guessing.
- Exclusions say "unavailable". Run the app as administrator.
- SmartScreen blocks the download. Expected for a new unsigned app. Verify the checksum, or build from source.
- Update check fails. It needs outbound access to
api.github.comandgithub.com.