<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	
	>
<channel>
	<title>Comments on: WMI, Query Windows SecurityCenter2</title>
	<atom:link href="http://neophob.com/2010/03/wmi-query-windows-securitycenter2/feed/" rel="self" type="application/rss+xml" />
	<link>http://neophob.com/2010/03/wmi-query-windows-securitycenter2/</link>
	<description>are you still afraid?</description>
	<lastBuildDate>Mon, 08 Jul 2019 19:58:13 +0000</lastBuildDate>
		<sy:updatePeriod>hourly</sy:updatePeriod>
		<sy:updateFrequency>1</sy:updateFrequency>
	<generator>https://wordpress.org/?v=3.9.40</generator>
	<item>
		<title>By: Pedro P. Polakoff III</title>
		<link>http://neophob.com/2010/03/wmi-query-windows-securitycenter2/#comment-35676</link>
		<dc:creator><![CDATA[Pedro P. Polakoff III]]></dc:creator>
		<pubDate>Wed, 13 Mar 2019 15:01:35 +0000</pubDate>
		<guid isPermaLink="false">http://192.168.111.20/wordpress/?p=153#comment-35676</guid>
		<description><![CDATA[The second byte is actually two bits with the first bit being the active state of the product and the second bit being the stae of realtime protection being disabled so that:
0x10 = Active &amp; Enabled
0x11 = Active &amp; Disabled
0x01 = Inactive &amp; Enabled (but not working)]]></description>
		<content:encoded><![CDATA[
Warning: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead in /home/httpd/vhosts/pixelinvaders.ch/httpdocs/neophob.com/wp-content/plugins/codecolorer/codecolorer-core.php on line 49

Warning: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead in /home/httpd/vhosts/pixelinvaders.ch/httpdocs/neophob.com/wp-content/plugins/codecolorer/codecolorer-core.php on line 50
]]></content:encoded>
	</item>
	<item>
		<title>By: Amushriprathi Cool</title>
		<link>http://neophob.com/2010/03/wmi-query-windows-securitycenter2/#comment-15779</link>
		<dc:creator><![CDATA[Amushriprathi Cool]]></dc:creator>
		<pubDate>Mon, 26 Feb 2018 07:04:15 +0000</pubDate>
		<guid isPermaLink="false">http://192.168.111.20/wordpress/?p=153#comment-15779</guid>
		<description><![CDATA[What is the product state 401664 for windows defender?]]></description>
		<content:encoded><![CDATA[
Warning: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead in /home/httpd/vhosts/pixelinvaders.ch/httpdocs/neophob.com/wp-content/plugins/codecolorer/codecolorer-core.php on line 49

Warning: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead in /home/httpd/vhosts/pixelinvaders.ch/httpdocs/neophob.com/wp-content/plugins/codecolorer/codecolorer-core.php on line 50
]]></content:encoded>
	</item>
	<item>
		<title>By: Check if antivirus software is running with an acceptable status or not?</title>
		<link>http://neophob.com/2010/03/wmi-query-windows-securitycenter2/#comment-4917</link>
		<dc:creator><![CDATA[Check if antivirus software is running with an acceptable status or not?]]></dc:creator>
		<pubDate>Sat, 07 Nov 2015 09:01:38 +0000</pubDate>
		<guid isPermaLink="false">http://192.168.111.20/wordpress/?p=153#comment-4917</guid>
		<description><![CDATA[[&#8230;] Try this: WMI, Query Windows SecurityCenter2 [&#8230;]]]></description>
		<content:encoded><![CDATA[
Warning: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead in /home/httpd/vhosts/pixelinvaders.ch/httpdocs/neophob.com/wp-content/plugins/codecolorer/codecolorer-core.php on line 49

Warning: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead in /home/httpd/vhosts/pixelinvaders.ch/httpdocs/neophob.com/wp-content/plugins/codecolorer/codecolorer-core.php on line 50
]]></content:encoded>
	</item>
	<item>
		<title>By: Mr. Blerg</title>
		<link>http://neophob.com/2010/03/wmi-query-windows-securitycenter2/#comment-4309</link>
		<dc:creator><![CDATA[Mr. Blerg]]></dc:creator>
		<pubDate>Fri, 12 Jun 2015 17:04:58 +0000</pubDate>
		<guid isPermaLink="false">http://192.168.111.20/wordpress/?p=153#comment-4309</guid>
		<description><![CDATA[I did a little poke using this at Bitdefender. Turns out when you disable your firewall in BitDefender, the &quot;SCANNER_SETTINGS&quot; goes to &quot;00&quot;. Minor change, but that didn&#039;t appear in your definition.]]></description>
		<content:encoded><![CDATA[
Warning: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead in /home/httpd/vhosts/pixelinvaders.ch/httpdocs/neophob.com/wp-content/plugins/codecolorer/codecolorer-core.php on line 49

Warning: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead in /home/httpd/vhosts/pixelinvaders.ch/httpdocs/neophob.com/wp-content/plugins/codecolorer/codecolorer-core.php on line 50
]]></content:encoded>
	</item>
	<item>
		<title>By: NSClient++ und darüber hinaus › NETWAYS Blog</title>
		<link>http://neophob.com/2010/03/wmi-query-windows-securitycenter2/#comment-4186</link>
		<dc:creator><![CDATA[NSClient++ und darüber hinaus › NETWAYS Blog]]></dc:creator>
		<pubDate>Fri, 22 May 2015 09:01:09 +0000</pubDate>
		<guid isPermaLink="false">http://192.168.111.20/wordpress/?p=153#comment-4186</guid>
		<description><![CDATA[[&#8230;] http://neophob.com/2010/03/wmi-query-windows-securitycenter2/ [&#8230;]]]></description>
		<content:encoded><![CDATA[
Warning: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead in /home/httpd/vhosts/pixelinvaders.ch/httpdocs/neophob.com/wp-content/plugins/codecolorer/codecolorer-core.php on line 49

Warning: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead in /home/httpd/vhosts/pixelinvaders.ch/httpdocs/neophob.com/wp-content/plugins/codecolorer/codecolorer-core.php on line 50
]]></content:encoded>
	</item>
	<item>
		<title>By: jgstew</title>
		<link>http://neophob.com/2010/03/wmi-query-windows-securitycenter2/#comment-2644</link>
		<dc:creator><![CDATA[jgstew]]></dc:creator>
		<pubDate>Tue, 13 May 2014 20:52:27 +0000</pubDate>
		<guid isPermaLink="false">http://192.168.111.20/wordpress/?p=153#comment-2644</guid>
		<description><![CDATA[Here are the productState values I have found from 34 different AV products across over 10000 endpoints:

( Decimal, Hex, Bit Set )

262144, 40000, 1000000000000000000

262160, 40010, 1000000000000010000

266240, 41000, 1000001000000000000

270336, 42000, 1000010000000000000

327680, 50000, 1010000000000000000

327696, 50010, 1010000000000010000

331776, 51000, 1010001000000000000

344064, 54000, 1010100000000000000

393216, 60000, 1100000000000000000

393232, 60010, 1100000000000010000

393472, 60100, 1100000000100000000

393488, 60110, 1100000000100010000

397312, 61000, 1100001000000000000

397328, 61010, 1100001000000010000

397568, 61100, 1100001000100000000

397584, 61110, 1100001000100010000

458752, 70000, 1110000000000000000

458768, 70010, 1110000000000010000

462848, 71000, 1110001000000000000

462864, 71010, 1110001000000010000]]></description>
		<content:encoded><![CDATA[
Warning: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead in /home/httpd/vhosts/pixelinvaders.ch/httpdocs/neophob.com/wp-content/plugins/codecolorer/codecolorer-core.php on line 49

Warning: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead in /home/httpd/vhosts/pixelinvaders.ch/httpdocs/neophob.com/wp-content/plugins/codecolorer/codecolorer-core.php on line 50
]]></content:encoded>
	</item>
	<item>
		<title>By: Monitoring Windows security products &#124; digirati82</title>
		<link>http://neophob.com/2010/03/wmi-query-windows-securitycenter2/#comment-2450</link>
		<dc:creator><![CDATA[Monitoring Windows security products &#124; digirati82]]></dc:creator>
		<pubDate>Wed, 04 Sep 2013 21:43:59 +0000</pubDate>
		<guid isPermaLink="false">http://192.168.111.20/wordpress/?p=153#comment-2450</guid>
		<description><![CDATA[[&#8230;] bit more research turned up some helpful posts, notably http://neophob.com/2010/03/wmi-query-windows-securitycenter2/, which lead to the creation of a `decodeProductState` macro. The macro converts the productState to [&#8230;]]]></description>
		<content:encoded><![CDATA[
Warning: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead in /home/httpd/vhosts/pixelinvaders.ch/httpdocs/neophob.com/wp-content/plugins/codecolorer/codecolorer-core.php on line 49

Warning: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead in /home/httpd/vhosts/pixelinvaders.ch/httpdocs/neophob.com/wp-content/plugins/codecolorer/codecolorer-core.php on line 50
]]></content:encoded>
	</item>
	<item>
		<title>By: Detect antivirus software using WMI and Powershell &#171; Soyka&#039;s Blog</title>
		<link>http://neophob.com/2010/03/wmi-query-windows-securitycenter2/#comment-846</link>
		<dc:creator><![CDATA[Detect antivirus software using WMI and Powershell &#171; Soyka&#039;s Blog]]></dc:creator>
		<pubDate>Wed, 22 Aug 2012 21:07:08 +0000</pubDate>
		<guid isPermaLink="false">http://192.168.111.20/wordpress/?p=153#comment-846</guid>
		<description><![CDATA[[...] http://neophob.com/2010/03/wmi-query-windows-securitycenter2/ [...]]]></description>
		<content:encoded><![CDATA[
Warning: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead in /home/httpd/vhosts/pixelinvaders.ch/httpdocs/neophob.com/wp-content/plugins/codecolorer/codecolorer-core.php on line 49

Warning: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead in /home/httpd/vhosts/pixelinvaders.ch/httpdocs/neophob.com/wp-content/plugins/codecolorer/codecolorer-core.php on line 50
]]></content:encoded>
	</item>
	<item>
		<title>By: William Mimart</title>
		<link>http://neophob.com/2010/03/wmi-query-windows-securitycenter2/#comment-560</link>
		<dc:creator><![CDATA[William Mimart]]></dc:creator>
		<pubDate>Fri, 02 Mar 2012 10:19:46 +0000</pubDate>
		<guid isPermaLink="false">http://192.168.111.20/wordpress/?p=153#comment-560</guid>
		<description><![CDATA[I&#039;ve made some C# code looking for  AntiVirus and AntiSpyware state of an Windows Station. If somebody is interested.... I&#039;ll share it.
mailto:william.mimart@gmail.com]]></description>
		<content:encoded><![CDATA[
Warning: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead in /home/httpd/vhosts/pixelinvaders.ch/httpdocs/neophob.com/wp-content/plugins/codecolorer/codecolorer-core.php on line 49

Warning: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead in /home/httpd/vhosts/pixelinvaders.ch/httpdocs/neophob.com/wp-content/plugins/codecolorer/codecolorer-core.php on line 50
]]></content:encoded>
	</item>
	<item>
		<title>By: Use Windows PowerShell to get antivirus product information - Jan Egil`s blog on Microsoft Infrastructure</title>
		<link>http://neophob.com/2010/03/wmi-query-windows-securitycenter2/#comment-363</link>
		<dc:creator><![CDATA[Use Windows PowerShell to get antivirus product information - Jan Egil`s blog on Microsoft Infrastructure]]></dc:creator>
		<pubDate>Sun, 12 Jun 2011 20:51:56 +0000</pubDate>
		<guid isPermaLink="false">http://192.168.111.20/wordpress/?p=153#comment-363</guid>
		<description><![CDATA[[...] in regards to definition updates and real-time protection. More information on this is available here. I haven`t found a complete reference to all possible values, the best I could find is available [...]]]></description>
		<content:encoded><![CDATA[
Warning: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead in /home/httpd/vhosts/pixelinvaders.ch/httpdocs/neophob.com/wp-content/plugins/codecolorer/codecolorer-core.php on line 49

Warning: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead in /home/httpd/vhosts/pixelinvaders.ch/httpdocs/neophob.com/wp-content/plugins/codecolorer/codecolorer-core.php on line 50
]]></content:encoded>
	</item>
	<item>
		<title>By: adam</title>
		<link>http://neophob.com/2010/03/wmi-query-windows-securitycenter2/#comment-257</link>
		<dc:creator><![CDATA[adam]]></dc:creator>
		<pubDate>Tue, 15 Mar 2011 17:52:44 +0000</pubDate>
		<guid isPermaLink="false">http://192.168.111.20/wordpress/?p=153#comment-257</guid>
		<description><![CDATA[This theory is holding up pretty well. I&#039;ll be integrating this into a script and running it against a few hundred machines with a myriad configurations. Looking forward to seeing how it works out. solid work dude]]></description>
		<content:encoded><![CDATA[
Warning: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead in /home/httpd/vhosts/pixelinvaders.ch/httpdocs/neophob.com/wp-content/plugins/codecolorer/codecolorer-core.php on line 49

Warning: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead in /home/httpd/vhosts/pixelinvaders.ch/httpdocs/neophob.com/wp-content/plugins/codecolorer/codecolorer-core.php on line 50
]]></content:encoded>
	</item>
	<item>
		<title>By: michu</title>
		<link>http://neophob.com/2010/03/wmi-query-windows-securitycenter2/#comment-256</link>
		<dc:creator><![CDATA[michu]]></dc:creator>
		<pubDate>Mon, 20 Dec 2010 07:33:54 +0000</pubDate>
		<guid isPermaLink="false">http://192.168.111.20/wordpress/?p=153#comment-256</guid>
		<description><![CDATA[Here is the response of MS:

Reading directly from rootsecuritycenter and rootsecuritycenter2 are not documented or supported interfaces.  As such, anyone who takes a dependency on them does so at their own risk.  We do not share the productState details outside of Windows, even under NDA.  Unfortunately, other than the WscGetSecurityProviderHealth interface, we don’t have a public interface to do what you are requesting at this time.]]></description>
		<content:encoded><![CDATA[
Warning: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead in /home/httpd/vhosts/pixelinvaders.ch/httpdocs/neophob.com/wp-content/plugins/codecolorer/codecolorer-core.php on line 49

Warning: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead in /home/httpd/vhosts/pixelinvaders.ch/httpdocs/neophob.com/wp-content/plugins/codecolorer/codecolorer-core.php on line 50
]]></content:encoded>
	</item>
	<item>
		<title>By: Gil Mier</title>
		<link>http://neophob.com/2010/03/wmi-query-windows-securitycenter2/#comment-255</link>
		<dc:creator><![CDATA[Gil Mier]]></dc:creator>
		<pubDate>Sun, 19 Dec 2010 13:54:56 +0000</pubDate>
		<guid isPermaLink="false">http://192.168.111.20/wordpress/?p=153#comment-255</guid>
		<description><![CDATA[Thanks.

Isn&#039;t NDA required only for registration of a FW/AV/anti-spyware?

Why is NDA required for asking about (an already) registered security components?]]></description>
		<content:encoded><![CDATA[
Warning: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead in /home/httpd/vhosts/pixelinvaders.ch/httpdocs/neophob.com/wp-content/plugins/codecolorer/codecolorer-core.php on line 49

Warning: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead in /home/httpd/vhosts/pixelinvaders.ch/httpdocs/neophob.com/wp-content/plugins/codecolorer/codecolorer-core.php on line 50
]]></content:encoded>
	</item>
	<item>
		<title>By: michu</title>
		<link>http://neophob.com/2010/03/wmi-query-windows-securitycenter2/#comment-254</link>
		<dc:creator><![CDATA[michu]]></dc:creator>
		<pubDate>Sun, 19 Dec 2010 11:17:09 +0000</pubDate>
		<guid isPermaLink="false">http://192.168.111.20/wordpress/?p=153#comment-254</guid>
		<description><![CDATA[You wont get an official response to that question, you need to sign a NDA if you want to use those information.]]></description>
		<content:encoded><![CDATA[
Warning: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead in /home/httpd/vhosts/pixelinvaders.ch/httpdocs/neophob.com/wp-content/plugins/codecolorer/codecolorer-core.php on line 49

Warning: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead in /home/httpd/vhosts/pixelinvaders.ch/httpdocs/neophob.com/wp-content/plugins/codecolorer/codecolorer-core.php on line 50
]]></content:encoded>
	</item>
	<item>
		<title>By: Gil Mier</title>
		<link>http://neophob.com/2010/03/wmi-query-windows-securitycenter2/#comment-253</link>
		<dc:creator><![CDATA[Gil Mier]]></dc:creator>
		<pubDate>Sun, 19 Dec 2010 11:03:53 +0000</pubDate>
		<guid isPermaLink="false">http://192.168.111.20/wordpress/?p=153#comment-253</guid>
		<description><![CDATA[Hi,

Did someone reach a formal answer for this?

Gil]]></description>
		<content:encoded><![CDATA[
Warning: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead in /home/httpd/vhosts/pixelinvaders.ch/httpdocs/neophob.com/wp-content/plugins/codecolorer/codecolorer-core.php on line 49

Warning: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead in /home/httpd/vhosts/pixelinvaders.ch/httpdocs/neophob.com/wp-content/plugins/codecolorer/codecolorer-core.php on line 50
]]></content:encoded>
	</item>
	<item>
		<title>By: michu</title>
		<link>http://neophob.com/2010/03/wmi-query-windows-securitycenter2/#comment-252</link>
		<dc:creator><![CDATA[michu]]></dc:creator>
		<pubDate>Wed, 27 Oct 2010 19:09:24 +0000</pubDate>
		<guid isPermaLink="false">http://192.168.111.20/wordpress/?p=153#comment-252</guid>
		<description><![CDATA[Thanks for your reply, Sam! About your issue:
&gt;the only real deviation I saw while testing was Symantec Endpoint Protection, which reported a WSC_SECURITY_PROVIDER of 7 while also claiming to not have a firewall...

this means that the product provide WSC_SECURITY_PROVIDER_FIREWALL (1), WSC_SECURITY_PROVIDER_AUTOUPDATE_SETTINGS (2) and WSC_SECURITY_PROVIDER_ANTIVIRUS (4). I guess this is right.

]]></description>
		<content:encoded><![CDATA[
Warning: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead in /home/httpd/vhosts/pixelinvaders.ch/httpdocs/neophob.com/wp-content/plugins/codecolorer/codecolorer-core.php on line 49

Warning: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead in /home/httpd/vhosts/pixelinvaders.ch/httpdocs/neophob.com/wp-content/plugins/codecolorer/codecolorer-core.php on line 50
]]></content:encoded>
	</item>
	<item>
		<title>By: Sam Bryan</title>
		<link>http://neophob.com/2010/03/wmi-query-windows-securitycenter2/#comment-251</link>
		<dc:creator><![CDATA[Sam Bryan]]></dc:creator>
		<pubDate>Wed, 27 Oct 2010 18:09:03 +0000</pubDate>
		<guid isPermaLink="false">http://192.168.111.20/wordpress/?p=153#comment-251</guid>
		<description><![CDATA[Ah, I&#039;ve been curious about this for a long time!  I think that your theory holds up very well, the only real deviation I saw while testing was Symantec Endpoint Protection, which reported a WSC_SECURITY_PROVIDER of 7 while also claiming to not have a firewall.  I&#039;m more than happy to believe that&#039;s an error on Symantec&#039;s part :)



McAfee VirusScan Enterprise 8.7
	266240 (0x041000) - Enabled, definitions are current
	262144 (0x040000) - On Access Scan disabled, definitions are current
	266256 (0x041010) - Enabled, definitions out of date


Microsoft Security Essentials
	397328 (0x061010) - Enabled, definitions out of date
	397312 (0x061000) - Enabled, definitions are current
	
	
Symantec Endpoint Protection 11.0 (Doesn&#039;t have a firewall, but does have email scanning etc.  Does have anti-spyware.)
	462864 (0x071010) - Enabled, definitions out of date
	462848 (0x071000) - Enabled, definitions are current
	
		
AVG Internet Security 2011
	266240 (0x041000) - Enabled, definitions are current
	
	
Sophos 9.0 (has client firewall)
	331776 (0x051000) - Enabled, definitions are current
	
	
Sunbelt VIPRE
	266240 (0x041000) - Enabled, definitions are current
	
	
Kaspersky 8.0
	266240 (0x041000) - Enabled, definitions are current]]></description>
		<content:encoded><![CDATA[
Warning: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead in /home/httpd/vhosts/pixelinvaders.ch/httpdocs/neophob.com/wp-content/plugins/codecolorer/codecolorer-core.php on line 49

Warning: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead in /home/httpd/vhosts/pixelinvaders.ch/httpdocs/neophob.com/wp-content/plugins/codecolorer/codecolorer-core.php on line 50
]]></content:encoded>
	</item>
</channel>
</rss>
