top of page

How to analyze PML file Defender AV

Writer's picture: Anand PAnand P

Updated: Jul 8, 2022

Hi, everyone in my previous blog I explained how to collect procmon for defender AV performance issues, in this blog I will explain how you can analyze the PML file and create an exclusion for AV performance.


If you haven't read my previous blog please find the link Use Procmon for Defender AV Performance Issues


Step 1: Open procmon and from file select open and navigate to the folder where you saved the PML or use Ctrl+O as a short key

Step 2:Navigate to the location where the file is saved in my case I have saved it in the same folder where procmon is saved now select the file and click on Open to open the file in Procmon

Step 3: You can add the below operators as additional which will reduce the noise in the logs and click OK.

Step 4: Navigate to tools and select File summary, this will create a file summary

Step 5: Tap on save to export the file summary as a CSV file

Step 6: provide a file name and save the file as CSV

Step 7: Open the CSV file and sort the read file bytes column from Highest to Lowest and you can see the process path as well you can use the values to identify the exclusion.


338 views0 comments

Recent Posts

See All

Comentários


2023-02-01_17-26-41.jpg
About Me

Thank you for taking the time to visit my website. My name is Anand P, and I work as a Senior Engineer in IT. This blog is dedicated to providing articles on various Microsoft technologies such as Intune, Azure AD, Microsoft Defender for Endpoint, Azure, EMS, M365, Security, and more. Most of the content on this blog is based on the solutions and issues I encounter in my everyday work, and I use this platform as a technical notebook to keep track of my findings. Please note that any views expressed in my posts on this site are solely my own. Also, any code, scripts, demos, or examples provided in the blog posts are only for illustration. I hope you find my blog posts informative and useful.

Never Miss a Post. Subscribe Now!

Thanks for submitting!

  • LinkedIn
  • YouTube

Copyright © 2024 by Cloud Tek Space.

bottom of page